Bug 1160477 - (CVE-2019-20352) VUL-1: CVE-2019-20352: nasm: heap-based buffer over-read via a crafted .asm file in set_text_free when called from expand_one_smacro in asm/preproc.c
(CVE-2019-20352)
VUL-1: CVE-2019-20352: nasm: heap-based buffer over-read via a crafted .asm f...
Status: RESOLVED WORKSFORME
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P5 - None : Minor
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/250402/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-01-08 16:52 UTC by Wolfgang Frisch
Modified: 2020-01-08 16:55 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Wolfgang Frisch 2020-01-08 16:52:11 UTC
CVE-2019-20352

In Netwide Assembler (NASM) 2.15rc0, a heap-based buffer over-read occurs (via a
crafted .asm file) in set_text_free when called from expand_one_smacro in
asm/preproc.c.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-20352
http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-20352.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20352
https://bugzilla.nasm.us/show_bug.cgi?id=3392636
Comment 1 Wolfgang Frisch 2020-01-08 16:55:29 UTC
`nasm` is supported in:

SUSE:SLE-12:Update (2.10.09-4.5.1)
SUSE:SLE-15:Update (2.13.02-1.17)

Following my investigation with valgrind,
I found no issue in either version of the package.