MEDIUM 5.5 Microsoft
CVE-2023-29581
yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE: although a libyasm application could become unavailable if this were exploited, the vendor's position is that there is no security relevance because there is either supposed to be input validation before data reaches libyasm, or a sandbox in which the application runs.
Microsoft Security Update 2023-Apr: yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE: although a libyasm application could become unavailable if this were exploited, the vendor's position is that there is no security relevance because there is either supposed to be input validation before data reaches libyasm, or a sandbox in which the application runs.
Affected Products
- azl3 yasm 1.3.0-17 on Azure Linux 3.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29581
- https://nvd.nist.gov/vuln/detail/CVE-2023-29581
This medium severity vulnerability with a CVSS score of 5.5 was published on 2023-04-11 via Microsoft. Affected: azl3 yasm 1.3.0-17 on Azure Linux 3.0.
vulnfeed aggregates 8294 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.