CVE-2017-12450Out-of-bounds Write in Binutils

CWE-787Out-of-bounds Write11 documents8 sources
Severity
7.8HIGHNVD
EPSS
0.4%
top 37.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 4
Latest updateMay 17

Description

The alpha_vms_object_p function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap write and possibly achieve code execution via a crafted vms alpha file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

Debiangnu/binutils< 2.29-9+3
NVDgnu/binutils2.29

Patches

🔴Vulnerability Details

3
GHSA
GHSA-c6m3-55h6-cpq4: The alpha_vms_object_p function in bfd/vms-alpha2022-05-17
OSV
CVE-2017-12450: The alpha_vms_object_p function in bfd/vms-alpha2017-08-04
CVEList
CVE-2017-12450: The alpha_vms_object_p function in bfd/vms-alpha2017-08-04

📋Vendor Advisories

3
Ubuntu
GNU binutils vulnerabilities2021-07-21
Red Hat
binutils: out of bounds heap write in alpha_vms_object_p function2017-07-21
Debian
CVE-2017-12450: binutils - The alpha_vms_object_p function in bfd/vms-alpha.c in the Binary File Descriptor...2017

💬Community

4
Bugzilla
CVE-2017-12448 CVE-2017-12449 CVE-2017-12450 CVE-2017-12451 CVE-2017-12452 CVE-2017-12453 CVE-2017-12454 CVE-2017-12455 CVE-2017-12456 CVE-2017-12457 CVE-2017-12458 CVE-2017-12459 CVE-2017-13710 CVE-22017-08-21
Bugzilla
CVE-2017-12448 CVE-2017-12449 CVE-2017-12450 CVE-2017-12451 CVE-2017-12452 CVE-2017-12453 CVE-2017-12454 CVE-2017-12455 CVE-2017-12456 CVE-2017-12457 CVE-2017-12458 CVE-2017-12459 CVE-2017-13710 CVE-22017-08-21
Bugzilla
CVE-2017-12448 CVE-2017-12449 CVE-2017-12450 CVE-2017-12451 CVE-2017-12452 CVE-2017-12453 CVE-2017-12454 CVE-2017-12455 CVE-2017-12456 CVE-2017-12457 CVE-2017-12458 CVE-2017-12459 CVE-2017-13710 CVE-22017-08-21
Bugzilla
CVE-2017-12450 binutils: out of bounds heap write in alpha_vms_object_p function2017-08-21
CVE-2017-12450 — Out-of-bounds Write in GNU Binutils | cvebase