CVE-2017-12453Out-of-bounds Read in Binutils

CWE-125Out-of-bounds Read11 documents8 sources
Severity
7.8HIGHNVD
EPSS
0.3%
top 42.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 4
Latest updateMay 17

Description

The _bfd_vms_slurp_eeom function in libbfd.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms alpha file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

Debiangnu/binutils< 2.29-9+3
NVDgnu/binutils2.29

Patches

🔴Vulnerability Details

3
GHSA
GHSA-fcq8-p7v9-54c3: The _bfd_vms_slurp_eeom function in libbfd2022-05-17
CVEList
CVE-2017-12453: The _bfd_vms_slurp_eeom function in libbfd2017-08-04
OSV
CVE-2017-12453: The _bfd_vms_slurp_eeom function in libbfd2017-08-04

📋Vendor Advisories

3
Ubuntu
GNU binutils vulnerabilities2021-07-21
Red Hat
binutils: out of bounds heap read in __bfd_vms_slurp_eeom function2017-07-21
Debian
CVE-2017-12453: binutils - The _bfd_vms_slurp_eeom function in libbfd.c in the Binary File Descriptor (BFD)...2017

💬Community

4
Bugzilla
CVE-2017-12448 CVE-2017-12449 CVE-2017-12450 CVE-2017-12451 CVE-2017-12452 CVE-2017-12453 CVE-2017-12454 CVE-2017-12455 CVE-2017-12456 CVE-2017-12457 CVE-2017-12458 CVE-2017-12459 CVE-2017-13710 CVE-22017-08-21
Bugzilla
CVE-2017-12453 binutils: out of bounds heap read in __bfd_vms_slurp_eeom function2017-08-21
Bugzilla
CVE-2017-12448 CVE-2017-12449 CVE-2017-12450 CVE-2017-12451 CVE-2017-12452 CVE-2017-12453 CVE-2017-12454 CVE-2017-12455 CVE-2017-12456 CVE-2017-12457 CVE-2017-12458 CVE-2017-12459 CVE-2017-13710 CVE-22017-08-21
Bugzilla
CVE-2017-12448 CVE-2017-12449 CVE-2017-12450 CVE-2017-12451 CVE-2017-12452 CVE-2017-12453 CVE-2017-12454 CVE-2017-12455 CVE-2017-12456 CVE-2017-12457 CVE-2017-12458 CVE-2017-12459 CVE-2017-13710 CVE-22017-08-21
CVE-2017-12453 — Out-of-bounds Read in GNU Binutils | cvebase