Vulnerability Description
In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nasm | Netwide Assembler | 2.15.04 |
Related Weaknesses (CWE)
References
- https://bugzilla.nasm.us/show_bug.cgi?id=3392712ExploitIssue TrackingVendor Advisory
- https://bugzilla.nasm.us/show_bug.cgi?id=3392712ExploitIssue TrackingVendor Advisory
FAQ
What is CVE-2020-24978?
CVE-2020-24978 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7.
How severe is CVE-2020-24978?
CVE-2020-24978 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-24978?
Check the references section above for vendor advisories and patch information. Affected products include: Nasm Netwide Assembler.