Vulnerability Description
In crasm 1.8-3, invalid input validation, specific files passed to the command line application, can lead to a NULL pointer dereference in the function Xasc.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Crasm Project | Crasm | < 1.11 |
Related Weaknesses (CWE)
References
- https://github.com/WhatTheFuzz/crasm-fuzz/tree/a020ad6ad99a72ca373f7dd1aab3a61a7ExploitThird Party Advisory
- https://github.com/colinbourassa/crasm/pull/7PatchThird Party Advisory
- https://github.com/WhatTheFuzz/crasm-fuzz/tree/a020ad6ad99a72ca373f7dd1aab3a61a7ExploitThird Party Advisory
- https://github.com/colinbourassa/crasm/pull/7PatchThird Party Advisory
FAQ
What is CVE-2023-23108?
CVE-2023-23108 is a vulnerability with a CVSS score of 7.5 (HIGH). In crasm 1.8-3, invalid input validation, specific files passed to the command line application, can lead to a NULL pointer dereference in the function Xasc.
How severe is CVE-2023-23108?
CVE-2023-23108 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-23108?
Check the references section above for vendor advisories and patch information. Affected products include: Crasm Project Crasm.