CVE-2017-12967: GNU Binutils
Medium severity, CVSS 6.5. EPSS: 3.1% chance of exploitation in the next 30 days.
The getsym function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a malformed tekhex binary.
Affected products
- GNU Binutils: version 2.29 only
Published 2017-08-19. Last modified 2026-06-17.