High severity7.8NVD Advisory· Published Aug 4, 2017· Updated May 13, 2026
CVE-2017-12450
CVE-2017-12450
Description
The alpha_vms_object_p function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap write and possibly achieve code execution via a crafted vms alpha file.
Affected products
17- osv-coords15 versionspkg:rpm/opensuse/binutils&distro=openSUSE%20Tumbleweedpkg:rpm/suse/binutils&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/binutils&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/binutils&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2pkg:rpm/suse/binutils&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/binutils&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2pkg:rpm/suse/binutils&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/binutils&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/binutils&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/binutils&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/binutils&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/cross-ppc-binutils&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/cross-ppc-binutils&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/cross-spu-binutils&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/cross-spu-binutils&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3
< 2.37-1.3+ 14 more
- (no CPE)range: < 2.37-1.3
- (no CPE)range: < 2.29.1-9.20.2
- (no CPE)range: < 2.29.1-9.20.2
- (no CPE)range: < 2.29.1-9.20.2
- (no CPE)range: < 2.29.1-9.20.2
- (no CPE)range: < 2.29.1-9.20.2
- (no CPE)range: < 2.29.1-9.20.2
- (no CPE)range: < 2.29.1-9.20.2
- (no CPE)range: < 2.29.1-9.20.2
- (no CPE)range: < 2.29.1-9.20.2
- (no CPE)range: < 2.29.1-9.20.2
- (no CPE)range: < 2.29.1-9.20.2
- (no CPE)range: < 2.29.1-9.20.2
- (no CPE)range: < 2.29.1-9.20.2
- (no CPE)range: < 2.29.1-9.20.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- sourceware.org/bugzilla/show_bug.cginvdIssue TrackingPatchThird Party Advisory
News mentions
0No linked articles in our index yet.