PT-2017-4272 · Gnu+3 · Gnu Binutils+3
Ned Williamson
·
Published
2017-07-21
·
Updated
2024-06-15
·
CVE-2017-12450
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
GNU Binutils versions 2.29 and earlier
Description:
The issue is related to the alpha vms object p function in the bfd/vms-alpha.c component of GNU Binutils, which is associated with a buffer overflow. This allows a remote attacker to access confidential data, compromise its integrity, and potentially cause a denial of service. The vulnerability can be exploited by remote attackers via a crafted vms alpha file, potentially leading to code execution.
Recommendations:
For GNU Binutils versions 2.29 and earlier, update to a version later than 2.29 to resolve the issue.
At the moment, there is no information about other specific fixes for this vulnerability.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Gnu Binutils
Suse
Ubuntu