First published: Fri Aug 04 2017(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Binutils | <=2.29 | |
debian/binutils | 2.35.2-2 2.40-2 2.43.1-5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12448 is a vulnerability in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.29 and earlier, which allows remote attackers to cause a heap use after free and possibly achieve code execution through a crafted nested archive file.
CVE-2017-12448 affects the Binutils package in Ubuntu versions 16.04.8+ (2.26.1-1ubuntu1~16.04.8+) and 18.04 (2.29.1).
The severity of CVE-2017-12448 is high.
The CWEs for CVE-2017-12448 are CWE-20 (Improper Input Validation) and CWE-416 (Use After Free).
To fix CVE-2017-12448, update the affected Binutils package to version 2.26.1-1ubuntu1~16.04.8+ (for Ubuntu 16.04.8+) or version 2.29.1 (for Ubuntu 18.04).