Summary: | dev-lang/nasm: multiple vulnerabilities | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | CONFIRMED --- | ||
Severity: | minor | CC: | matthew, proxy-maint |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugzilla.nasm.us/show_bug.cgi?id=3392568 | ||
Whiteboard: | B3 [upstream] | ||
Package list: | Runtime testing required: | --- |
Description
John Helmert III
![]() ![]() ![]() ![]() CVE-2021-45256 (https://bugzilla.nasm.us/show_bug.cgi?id=3392789): A Null Pointer Dereference vulnerability existfs in nasm 2.16rc0 via asm/preproc.c. CVE-2021-45257 (https://bugzilla.nasm.us/show_bug.cgi?id=3392790): An infinite loop vulnerability exists in nasm 2.16rc0 via the gpaste_tokens function. Can't tell if there's been any action taken upstream as their Bugzilla seems to be down. |