Integer overflow in lzo - CVE-2014-4607
Published: February 12, 2020 / Updated: July 28, 2020
Vulnerability identifier: #VU32506
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-4607
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.
Affected software
lzo
Gentoo Linux
Amazon Linux AMI
Fedora
SUSE Linux
lzo (Alpine package)
dump
icecream
grub2
distcc
Gentoo Linux
Amazon Linux AMI
Fedora
SUSE Linux
lzo (Alpine package)
dump
icecream
grub2
distcc
How to mitigate CVE-2014-4607
Install update from vendor's website.
lzo (Alpine package) - update to 2.08-r0
dump - update to 0.4-0.24.b44.fc21
icecream - update to 1.0.1-8.20140822git.fc21
grub2 - update to 2.02-0.13.fc21
distcc - update to 3.2 rc1-2.el6
dump - update to 0.4-0.24.b44.fc21
icecream - update to 1.0.1-8.20140822git.fc21
grub2 - update to 2.02-0.13.fc21
distcc - update to 3.2 rc1-2.el6
External References
Related Security Bulletins
- Integer overflow in www.oberhumer.com lzo
- Integer overflow in lzo (Alpine package)
- SUSE Linux update for lzo
- SUSE Linux update for lzo
- Amazon Linux AMI update for lzo
- Gentoo update for LZO
- Gentoo update for BusyBox
- Fedora EPEL 6 update for distcc
- Fedora 21 update for icecream
- Fedora 21 update for grub2
- Fedora 21 update for dump