The bfdvmssavesized_string function in vms-misc.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms file.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-12449.json"