CVE-2017-12459

HIGH

GNU Binutils < 2.29 - Out-of-bounds Write via Crafted Mach-O File

Title source: llm
STIX 2.1

Description

The bfd_mach_o_read_symtab_strtab function in bfd/mach-o.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap write and possibly achieve code execution via a crafted mach-o file.

References (1)

Core 1
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://sourceware.org/bugzilla/show_bug.cgi?id=21840

Scores

CVSS v3 7.8
EPSS 0.0042
EPSS Percentile 62.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (1)
gnu/binutils < 2.29
Published Aug 04, 2017
Tracked Since Feb 18, 2026