CVE-2023-23108: Crasm Project Crasm
High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.
In crasm 1.8-3, invalid input validation, specific files passed to the command line application, can lead to a NULL pointer dereference in the function Xasc.
Affected products
- Crasm Project Crasm: before 1.11 (fixed in 1.11)
Published 2023-02-27. Last modified 2026-06-17.