CVE-2018-1000667: Nasm Netwide Assembler

Medium severity, CVSS 5.5. EPSS: 1.2% chance of exploitation in the next 30 days.

NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory corruption (crashed) of nasm when handling a crafted file due to function assemble_file(inname, depend_ptr) at asm/nasm.c:482. vulnerability in function assemble_file(inname, depend_ptr) at asm/nasm.c:482. that can result in aborting/crash nasm program. This attack appear to be exploitable via a specially crafted asm file..

Affected products

  • Nasm Netwide Assembler: up to and including 2.14.0; version 2.14.0 only

Published 2018-09-06. Last modified 2026-06-17.