CVE-2017-12453

Published: 04 August 2017

The _bfd_vms_slurp_eeom function in libbfd.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms alpha file.

Priority

Low

CVSS 3 base score: 7.8

Status

Package Release Status
binutils
Launchpad, Ubuntu, Debian
Upstream
Released (2.29.1)
Ubuntu 20.10 (Groovy Gorilla) Not vulnerable
(2.29.1-1ubuntu1)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(2.29.1-1ubuntu1)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(2.29.1-1ubuntu1)
Ubuntu 16.04 LTS (Xenial Xerus) Needed

Ubuntu 14.04 ESM (Trusty Tahr) Needed

Patches:
Other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=ca4cf9b9c622a5695e01f7f5815a7382a31fcf51