>> NASM "ppscan()" Function Off-by-one Buffer Overflow Vulnerability
Title : NASM "ppscan()" Function Off-by-one Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2008-1811 CVE ID : CVE-2008-2719 CWE ID : CWE-193
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-06-11
Technical Description
A vulnerability has been identified in NASM, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by an off-by-one buffer overflow error in the "ppscan()" [preproc.c] function when processing ASM files, which could be exploited by attackers to crash an affected application or execute arbitrary code by tricking a user into assembling a specially crafted ASM file.