CVE-2017-12450
Published: 04 August 2017
The alpha_vms_object_p function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap write and possibly achieve code execution via a crafted vms alpha file.
Priority
CVSS 3 base score: 7.8
Status
Package | Release | Status |
---|---|---|
binutils Launchpad, Ubuntu, Debian |
Upstream |
Released
(2.29.1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Not vulnerable
(2.29.1-1ubuntu1)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Not vulnerable
(2.29.1-1ubuntu1)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Not vulnerable
(2.29.1-1ubuntu1)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Needed
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Needed
|
|
Patches: Other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=ca4cf9b9c622a5695e01f7f5815a7382a31fcf51 Other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=8a2df5e2df374289e00ecd8f099eb46d76ef982e Other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=deeb3d27c254ad8bf8c3877fa6b61817f56191f5 (v2.29 branch) Other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=64aa1246572306b72dc479b46d13ff749b0c3236 (v2.29 branch) |