CVE-2014-4607

Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
VendorProductVersion
oberhumerliblzo2
𝑥
< 2.07
oberhumerlzo2
𝑥
< 2.07
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
busybox
bullseye
1:1.30.1-6
fixed
wheezy
no-dsa
squeeze
no-dsa
bookworm
1:1.35.0-4
fixed
sid
1:1.37.0-4
fixed
trixie
1:1.37.0-4
fixed
lzo2
bookworm
2.10-2
fixed
bullseye
2.10-2
fixed
wheezy
no-dsa
squeeze
no-dsa
sid
2.10-3
fixed
trixie
2.10-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
grub2
noble
Fixed 2.04-1ubuntu37
released
mantic
Fixed 2.04-1ubuntu37
released
lunar
Fixed 2.04-1ubuntu37
released
kinetic
Fixed 2.04-1ubuntu37
released
jammy
Fixed 2.04-1ubuntu37
released
impish
Fixed 2.04-1ubuntu37
released
hirsute
Fixed 2.04-1ubuntu37
released
groovy
Fixed 2.04-1ubuntu35.2
released
focal
Fixed 2.04-1ubuntu26.8
released
bionic
not-affected
xenial
not-affected
trusty
not-affected
grub2-signed
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
Fixed 1.157
released
hirsute
Fixed 1.157
released
groovy
Fixed 1.155.2
released
focal
Fixed 1.142.10
released
bionic
not-affected
xenial
not-affected
trusty
not-affected
grub2-unsigned
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
focal
Fixed 2.04-1ubuntu47.4
released
bionic
not-affected
xenial
not-affected
trusty
dne
krfb
noble
Fixed 4:4.13.97-0ubuntu2
released
mantic
Fixed 4:4.13.97-0ubuntu2
released
lunar
Fixed 4:4.13.97-0ubuntu2
released
kinetic
Fixed 4:4.13.97-0ubuntu2
released
jammy
Fixed 4:4.13.97-0ubuntu2
released
impish
Fixed 4:4.13.97-0ubuntu2
released
hirsute
Fixed 4:4.13.97-0ubuntu2
released
groovy
Fixed 4:4.13.97-0ubuntu2
released
focal
Fixed 4:4.13.97-0ubuntu2
released
bionic
Fixed 4:4.13.97-0ubuntu2
released
xenial
Fixed 4:4.13.97-0ubuntu2
released
trusty
Fixed 4:4.13.0-0ubuntu1.1
released
precise
dne
lucid
dne
lzo2
noble
Fixed 2.06-1.2ubuntu2
released
mantic
Fixed 2.06-1.2ubuntu2
released
lunar
Fixed 2.06-1.2ubuntu2
released
kinetic
Fixed 2.06-1.2ubuntu2
released
jammy
Fixed 2.06-1.2ubuntu2
released
impish
Fixed 2.06-1.2ubuntu2
released
hirsute
Fixed 2.06-1.2ubuntu2
released
groovy
Fixed 2.06-1.2ubuntu2
released
focal
Fixed 2.06-1.2ubuntu2
released
bionic
Fixed 2.06-1.2ubuntu2
released
xenial
Fixed 2.06-1.2ubuntu2
released
trusty
Fixed 2.06-1.2ubuntu1.1
released
saucy
ignored
precise
Fixed 2.06-1ubuntu0.1
released
lucid
ignored