PT-2017-4272 · Gnu+3 · Gnu Binutils+3

Ned Williamson

·

Published

2017-07-21

·

Updated

2024-06-15

·

CVE-2017-12450

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: GNU Binutils versions 2.29 and earlier
Description: The issue is related to the alpha vms object p function in the bfd/vms-alpha.c component of GNU Binutils, which is associated with a buffer overflow. This allows a remote attacker to access confidential data, compromise its integrity, and potentially cause a denial of service. The vulnerability can be exploited by remote attackers via a crafted vms alpha file, potentially leading to code execution.
Recommendations: For GNU Binutils versions 2.29 and earlier, update to a version later than 2.29 to resolve the issue. At the moment, there is no information about other specific fixes for this vulnerability.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1603
ALT-PU-2018-1832
ALT-PU-2019-1184
BDU:2023-07727
CVE-2017-12450
MGASA-2019-0169
OPENSUSE-SU-2024:10651-1
SUSE-SU-2017:3170-1
USN-4336-2

Affected Products

Alt Linux
Gnu Binutils
Suse
Ubuntu