Home

Description

YASM v1.3.0 was discovered to contain a heap overflow via the function handle_dot_label at /nasm/nasm-token.re. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code.

PUBLISHED Reserved 2023-04-07 | Published 2023-04-25 | Updated 2024-08-02 | Assigner mitre

References

github.com/yasm/yasm/issues/206

cve.org (CVE-2023-30402)

nvd.nist.gov (CVE-2023-30402)

Download JSON