[CVE-2008-2719] nasm vulnerability (DoS and possible arbitrary code execution)

Bug #241421 reported by Till Ulen
256
Affects Status Importance Assigned to Milestone
nasm (Debian)
Fix Released
Unknown
nasm (Ubuntu)
Fix Released
Undecided
Unassigned
Dapper
Invalid
Undecided
Unassigned
Feisty
Invalid
Undecided
Unassigned
Gutsy
Invalid
Undecided
Unassigned
Hardy
Fix Released
Low
Kees Cook
Intrepid
Fix Released
Undecided
Unassigned

Bug Description

Binary package hint: nasm

CVE-2008-2719 description:

"Off-by-one error in the ppscan function (preproc.c) in Netwide Assembler (NASM) 2.02 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted file that triggers a stack-based buffer overflow."

http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2719

CVE References

Changed in nasm:
status: Unknown → Fix Released
Revision history for this message
Till Ulen (tillulen) wrote :

CVE-2008-2719

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Here is a debdiff for Hardy.

Changed in nasm:
status: New → In Progress
Kees Cook (kees)
Changed in nasm:
status: New → In Progress
status: In Progress → Fix Released
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

nasm 0.98.38 present in Dapper, Feisty and Gutsy does not seem to be vulnerable to the off-by-one bug. Affected code is not present.

Changed in nasm:
status: New → Invalid
status: New → Invalid
status: New → Invalid
Changed in nasm:
status: In Progress → Fix Committed
Revision history for this message
Kees Cook (kees) wrote :

This problem has been addressed with the following USN:

http://www.ubuntu.com/usn/usn-648-1

Changed in nasm:
assignee: nobody → kees
importance: Undecided → Low
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.