Bugzilla – Bug 1213700
VUL-0: CVE-2023-37732: yasm: SEGV in yasm/libyasm/intnum.c's function :yasm_intnum_copy
Last modified: 2023-08-30 10:15:45 UTC
Yasm v1.3.0.78 was found prone to NULL Pointer Dereference in /libyasm/intnum.c and /elf/elf.c, which allows the attacker to cause a denial of service via a crafted file. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-37732 https://bugzilla.redhat.com/show_bug.cgi?id=2226934 https://www.cve.org/CVERecord?id=CVE-2023-37732 https://gist.github.com/ChanStormstout/02eea9cf5c002b42b2ff3de5ca939520 https://github.com/yasm/yasm/issues/233
Please submit the upstream patch [0] to the following vulnerable packages: - SUSE:ALP:Source:Standard:1.0/yasm - SUSE:SLE-12:Update/yasm - openSUSE:Factory/yasm - SUSE:SLE-15:Update/yasm [0] https://github.com/yasm/yasm/commit/2cd3bb50e256f5ed5f611ac611d25fe673f2cec3.patch
Great, thanks for the explanation. Closing as WONTFIX.