Lucene search

K
redosRedosROS-20240904-06
HistorySep 04, 2024 - 12:00 a.m.

ROS-20240904-06

2024-09-0400:00:00
redos.red-soft.ru
yasm assembler
vulnerability
memory release
exploitation
sensitive data
attacker
unix

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

AI Score

6.9

Confidence

Low

A vulnerability in the yasm_intnum_copy function of the YASM assembler is related to the lack of memory release after the
effective lifetime. Exploitation of the vulnerability could allow an attacker to gain access to the
sensitive data

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64yasm< 1.3.0-8UNKNOWN

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

AI Score

6.9

Confidence

Low