CVE-2017-12455: High severity binutils vulnerability
Last updated 24 July 2024
Other sources
The evaxbfdprintemh function in vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms alpha file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2017-12455.
What is the affected software?
The affected software is the Binary File Descriptor (BFD) library, specifically GNU Binutils version 2.29 and earlier.
What is the impact of this vulnerability?
This vulnerability allows remote attackers to cause an out of bounds heap read.
Is there a fix available for this vulnerability?
Yes, there are fixes available for this vulnerability. Ubuntu users can upgrade to version 2.26.1-1ubuntu1~16.04.8+ or later. Debian users can upgrade to version 2.31.1-16, 2.35.2-2, 2.40-2, or 2.41-5.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [Bugzilla](https://sourceware.org/bugzilla/show_bug.cgi?id=21840), [Launchpad](https://launchpad.net/bugs/cve/CVE-2017-12455), [CVE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12455).