Vulnerability Description
The bfd_mach_o_read_symtab_strtab function in bfd/mach-o.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap write and possibly achieve code execution via a crafted mach-o file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Binutils | <= 2.29 |
Related Weaknesses (CWE)
References
- https://sourceware.org/bugzilla/show_bug.cgi?id=21840Issue TrackingPatchThird Party Advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=21840Issue TrackingPatchThird Party Advisory
FAQ
What is CVE-2017-12459?
CVE-2017-12459 is a vulnerability with a CVSS score of 7.8 (HIGH). The bfd_mach_o_read_symtab_strtab function in bfd/mach-o.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause a...
How severe is CVE-2017-12459?
CVE-2017-12459 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-12459?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Binutils.