CVE-2017-12448 is a heap use-after-free vulnerability in the Binary File Descriptor (BFD) library (libbfd), specifically in the bfd_cache_close function, affecting GNU Binutils 2.29 and earlier. This flaw allows remote attackers to potentially achieve code execution by crafting a malicious nested archive file, due to incorrect memory release functions being called. With a CVSS score of 7.8 (High), this vulnerability requires user interaction (UI:R) and local access (AV:L) but has high impacts on confidentiality, integrity, and availability. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.29CPE matchmatch criteria | cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.