CVE-2023-23108

In crasm 1.8-3, invalid input validation, specific files passed to the command line application, can lead to a NULL pointer dereference in the function Xasc.
Configurations

Configuration 1 (hide)

cpe:2.3:a:crasm_project:crasm:*:*:*:*:*:*:*:*

History

18 May 2023, 18:03

Type Values Removed Values Added
CPE cpe:2.3:a:crasm_project:crasm:1.8-3:*:*:*:*:*:*:* cpe:2.3:a:crasm_project:crasm:*:*:*:*:*:*:*:*

06 Mar 2023, 19:54

Type Values Removed Values Added
CWE CWE-476
First Time Crasm Project crasm
Crasm Project
References (MISC) https://github.com/WhatTheFuzz/crasm-fuzz/tree/a020ad6ad99a72ca373f7dd1aab3a61a7c87fd66/bug-null-pointer - (MISC) https://github.com/WhatTheFuzz/crasm-fuzz/tree/a020ad6ad99a72ca373f7dd1aab3a61a7c87fd66/bug-null-pointer - Exploit, Third Party Advisory
References (MISC) https://github.com/colinbourassa/crasm/pull/7 - (MISC) https://github.com/colinbourassa/crasm/pull/7 - Patch, Third Party Advisory
CPE cpe:2.3:a:crasm_project:crasm:1.8-3:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

27 Feb 2023, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-27 14:15

Updated : 2023-12-10 14:48


NVD link : CVE-2023-23108

Mitre link : CVE-2023-23108

CVE.ORG link : CVE-2023-23108


JSON object : View

Products Affected

crasm_project

  • crasm
CWE
CWE-476

NULL Pointer Dereference