CVE-2008-2719
NASM 2.0 - 'ppscan()' Off-by-One Buffer Overflow
Severity Score
6.8
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Off-by-one error in the ppscan function (preproc.c) in Netwide Assembler (NASM) 2.02 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted file that triggers a stack-based buffer overflow.
Error de superación de límite (off-by-one) en la función ppscan (prepoc.c) de Netwide Assembler (NASM) 2.02; permite a atacantes dependientes del contexto provocar una denegación de servicio (caída) y puede que ejecutar código de su elección mediante un fichero manipulado que produce un desbordamiento del búfer basado en pila.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2008-06-16 CVE Reserved
- 2008-06-16 CVE Published
- 2008-06-21 First Exploit
- 2024-08-07 CVE Updated
- 2024-11-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-189: Numeric Errors
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://repo.or.cz/w/nasm.git?a=commit%3Bh=76ec8e73db16f4cf1453a142d03bcc74d528f72f | X_refsource_confirm | |
http://secunia.com/advisories/32059 | Third Party Advisory | |
http://www.openwall.com/lists/oss-security/2008/06/11/4 | Mailing List | |
http://www.openwall.com/lists/oss-security/2008/06/11/5 | Mailing List | |
http://www.securityfocus.com/bid/29656 | Vdb Entry | |
http://www.securitytracker.com/id?1020259 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/1811 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42995 | Vdb Entry | |
https://sourceforge.net/project/shownotes.php?group_id=6208&release_id=606115 | X_refsource_confirm | |
https://sourceforge.net/tracker/?func=detail&atid=106208&aid=1942146&group_id=6208 | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/31903 | 2008-06-21 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/30594 | 2023-11-07 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2008:120 | 2023-11-07 | |
http://www.ubuntu.com/usn/usn-648-1 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nasm Search vendor "Nasm" | Netwide Assembler Search vendor "Nasm" for product "Netwide Assembler" | 2.02 Search vendor "Nasm" for product "Netwide Assembler" and version "2.02" | - |
Affected
|