CVE-2017-12450: High severity GNU binutils vulnerability
Last updated 24 July 2024
Other sources
The alphavmsobjectp function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap write and possibly achieve code execution via a crafted vms alpha file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-12450?
CVE-2017-12450 is a vulnerability in the Binary File Descriptor (BFD) library that allows remote attackers to cause an out of bounds heap write and possibly achieve code execution via a crafted vms alpha file.
How does CVE-2017-12450 impact my system?
CVE-2017-12450 can allow remote attackers to execute arbitrary code by exploiting the vulnerability in the BFD library.
Which software versions are affected by CVE-2017-12450?
Versions of Binutils prior to 2.29 are affected by CVE-2017-12450.
Is there a fix available for CVE-2017-12450?
Yes, the vulnerability has been fixed in version 2.29.1 of Binutils.
Where can I find more information about CVE-2017-12450?
You can find more information about CVE-2017-12450 on the following sources: [Bugzilla](https://sourceware.org/bugzilla/show_bug.cgi?id=21813), [Launchpad](https://launchpad.net/bugs/cve/CVE-2017-12450), and [CVE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12450).