CVE-2023-31975

Name
CVE-2023-31975
Description
yasm v1.3.0 was discovered to contain a memory leak via the function yasm_intnum_copy at /libyasm/intnum.c.
NVD Severity
low
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/yasm/yasm/issues/210
Mailing List http://www.openwall.com/lists/oss-security/2023/06/20/6
Mailing List http://www.openwall.com/lists/oss-security/2023/06/21/2
Mailing List http://www.openwall.com/lists/oss-security/2023/06/21/7
Mailing List http://www.openwall.com/lists/oss-security/2023/06/21/8
Mailing List http://www.openwall.com/lists/oss-security/2023/06/21/5
Mailing List http://www.openwall.com/lists/oss-security/2023/06/21/9
Mailing List http://www.openwall.com/lists/oss-security/2023/06/21/10
Mailing List http://www.openwall.com/lists/oss-security/2023/06/21/13
Mailing List http://www.openwall.com/lists/oss-security/2023/06/22/1
Mailing List http://www.openwall.com/lists/oss-security/2023/06/22/3
Mailing List http://www.openwall.com/lists/oss-security/2023/06/22/6
Mailing List http://www.openwall.com/lists/oss-security/2023/06/23/1
Mailing List http://www.openwall.com/lists/oss-security/2023/06/23/2
Mailing List http://www.openwall.com/lists/oss-security/2023/06/23/4
Mailing List http://www.openwall.com/lists/oss-security/2023/06/23/9
Mailing List http://www.openwall.com/lists/oss-security/2023/06/23/8
Mailing List http://www.openwall.com/lists/oss-security/2023/06/24/1

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:tortall:yasm:1.3.0:*:*:*:*:*:*:* yasm == None == 1.3.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
yasm 3.17-main 1.3.0-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
yasm 3.16-main 1.3.0-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
yasm 3.15-main 1.3.0-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
yasm 3.14-main 1.3.0-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
yasm edge-community 1.3.0-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
yasm 3.18-main 1.3.0-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable