CVE-2017-12450

Published: 04 August 2017

The alpha_vms_object_p function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap write and possibly achieve code execution via a crafted vms alpha file.

Priority

Low

CVSS 3 base score: 7.8

Status

Package Release Status
binutils
Launchpad, Ubuntu, Debian
Upstream
Released (2.29.1)
Ubuntu 21.04 (Hirsute Hippo) Not vulnerable
(2.29.1-1ubuntu1)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(2.29.1-1ubuntu1)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(2.29.1-1ubuntu1)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (2.26.1-1ubuntu1~16.04.8+esm1)
Ubuntu 14.04 ESM (Trusty Tahr) Needed

Patches:
Other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=ca4cf9b9c622a5695e01f7f5815a7382a31fcf51
Other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=8a2df5e2df374289e00ecd8f099eb46d76ef982e
Other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=deeb3d27c254ad8bf8c3877fa6b61817f56191f5 (v2.29 branch)
Other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=64aa1246572306b72dc479b46d13ff749b0c3236 (v2.29 branch)