﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
1513	Security fix for yet another nasm buffer overflow.	ken@…	bdubbs@…	"Nasm-0.98.39 fixed the CAN-2004-1287 buffer overflow.  The following patch taken
from CVS addresses CAN-2005-1194.  Vulnerability is probably low.

 I've just submitted this with the proper headers to patches as
nasm-0.98.39-security_fix-1.patch. Ken

--- nasm-0.98.39/output/outieee.c.orig  2005-01-15 22:16:08.000000000 +0000
+++ nasm-0.98.39/output/outieee.c       2005-08-08 22:12:46.000000000 +0100
@@ -1120,7 +1120,7 @@
     va_list ap;

     va_start(ap, format);
-    vsprintf(buffer, format, ap);
+    vsnprintf(buffer, sizeof(buffer), format, ap);
     l = strlen(buffer);
     for (i = 0; i < l; i++)
         if ((buffer[i] & 0xff) > 31)"	defect	closed	highest		BOOK	b-6.1-pre1	medium	fixed		
