CVE-2014-4607

Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
Affected Products (NVD)
VendorProductVersion
oberhumerliblzo2
𝑥
< 2.07
oberhumerlzo2
𝑥
< 2.07
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
busybox
bookworm
1:1.35.0-4
fixed
bullseye
1:1.30.1-6
fixed
sid
1:1.37.0-4
fixed
squeeze
no-dsa
trixie
1:1.37.0-4
fixed
wheezy
no-dsa
lzo2
bookworm
2.10-2
fixed
bullseye
2.10-2
fixed
sid
2.10-3
fixed
squeeze
no-dsa
trixie
2.10-3
fixed
wheezy
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
grub2
bionic
not-affected
focal
Fixed 2.04-1ubuntu26.8
released
groovy
Fixed 2.04-1ubuntu35.2
released
hirsute
Fixed 2.04-1ubuntu37
released
impish
Fixed 2.04-1ubuntu37
released
jammy
Fixed 2.04-1ubuntu37
released
kinetic
Fixed 2.04-1ubuntu37
released
lunar
Fixed 2.04-1ubuntu37
released
mantic
Fixed 2.04-1ubuntu37
released
noble
Fixed 2.04-1ubuntu37
released
trusty
not-affected
xenial
not-affected
grub2-signed
bionic
not-affected
focal
Fixed 1.142.10
released
groovy
Fixed 1.155.2
released
hirsute
Fixed 1.157
released
impish
Fixed 1.157
released
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
not-affected
xenial
not-affected
grub2-unsigned
bionic
not-affected
focal
Fixed 2.04-1ubuntu47.4
released
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
dne
xenial
not-affected
krfb
bionic
Fixed 4:4.13.97-0ubuntu2
released
focal
Fixed 4:4.13.97-0ubuntu2
released
groovy
Fixed 4:4.13.97-0ubuntu2
released
hirsute
Fixed 4:4.13.97-0ubuntu2
released
impish
Fixed 4:4.13.97-0ubuntu2
released
jammy
Fixed 4:4.13.97-0ubuntu2
released
kinetic
Fixed 4:4.13.97-0ubuntu2
released
lucid
dne
lunar
Fixed 4:4.13.97-0ubuntu2
released
mantic
Fixed 4:4.13.97-0ubuntu2
released
noble
Fixed 4:4.13.97-0ubuntu2
released
precise
dne
trusty
Fixed 4:4.13.0-0ubuntu1.1
released
xenial
Fixed 4:4.13.97-0ubuntu2
released
lzo2
bionic
Fixed 2.06-1.2ubuntu2
released
focal
Fixed 2.06-1.2ubuntu2
released
groovy
Fixed 2.06-1.2ubuntu2
released
hirsute
Fixed 2.06-1.2ubuntu2
released
impish
Fixed 2.06-1.2ubuntu2
released
jammy
Fixed 2.06-1.2ubuntu2
released
kinetic
Fixed 2.06-1.2ubuntu2
released
lucid
ignored
lunar
Fixed 2.06-1.2ubuntu2
released
mantic
Fixed 2.06-1.2ubuntu2
released
noble
Fixed 2.06-1.2ubuntu2
released
precise
Fixed 2.06-1ubuntu0.1
released
saucy
ignored
trusty
Fixed 2.06-1.2ubuntu1.1
released
xenial
Fixed 2.06-1.2ubuntu2
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
liblzo2-2
suse enterprise desktop 15
2.10-2.22
fixed
suse enterprise desktop 15 SP1
2.10-2.22
fixed
suse enterprise desktop 15 SP2
2.10-2.22
fixed
suse enterprise desktop 15 SP3
2.10-2.22
fixed
suse enterprise desktop 15 SP4
2.10-2.22
fixed
suse enterprise desktop 15 SP5
2.10-2.22
fixed
suse enterprise desktop 15 SP6
2.10-2.22
fixed
suse enterprise desktop 15 SP7
2.10-2.22
fixed
suse enterprise sap 12 SP5
2.08-1.13
fixed
suse enterprise sap 15
2.10-2.22
fixed
suse enterprise sap 15 SP1
2.10-2.22
fixed
suse enterprise sap 15 SP2
2.10-2.22
fixed
suse enterprise sap 15 SP3
2.10-2.22
fixed
suse enterprise sap 15 SP4
2.10-2.22
fixed
suse enterprise sap 15 SP5
2.10-2.22
fixed
suse enterprise sap 15 SP6
2.10-2.22
fixed
suse enterprise sap 15 SP7
2.10-2.22
fixed
suse enterprise server 12
2.08-1.6
fixed
suse enterprise server 12 SP1
2.08-1.13
fixed
suse enterprise server 12 SP2
2.08-1.6
fixed
suse enterprise server 12 SP3
2.08-1.6
fixed
suse enterprise server 12 SP4
2.08-1.6
fixed
suse enterprise server 12 SP5
2.08-1.6
fixed
suse enterprise server 15
2.10-2.22
fixed
suse enterprise server 15 SP1
2.10-2.22
fixed
suse enterprise server 15 SP2
2.10-2.22
fixed
suse enterprise server 15 SP3
2.10-2.22
fixed
suse enterprise server 15 SP4
2.10-2.22
fixed
suse enterprise server 15 SP5
2.10-2.22
fixed
suse enterprise server 15 SP6
2.10-2.22
fixed
suse enterprise server 15 SP7
2.10-2.22
fixed
liblzo2-2-32bit
suse enterprise sap 12 SP5
2.08-1.13
fixed
suse enterprise server 12
2.08-1.13
fixed
suse enterprise server 12 SP1
2.08-1.13
fixed
suse enterprise server 12 SP2
2.08-1.13
fixed
suse enterprise server 12 SP3
2.08-1.13
fixed
suse enterprise server 12 SP4
2.08-1.13
fixed
suse enterprise server 12 SP5
2.08-1.13
fixed
libvncclient0
suse enterprise desktop 15 SP2
0.9.10-4.14.1
fixed
suse enterprise desktop 15 SP3
0.9.10-4.25.1
fixed
suse enterprise sap 15 SP2
0.9.10-4.14.1
fixed
suse enterprise sap 15 SP3
0.9.10-4.25.1
fixed
suse enterprise server 15 SP2
0.9.10-4.14.1
fixed
suse enterprise server 15 SP3
0.9.10-4.25.1
fixed
suse enterprise workstation 15 SP2
0.9.10-4.14.1
fixed
suse enterprise workstation 15 SP3
0.9.10-4.25.1
fixed
libvncclient1
suse enterprise desktop 15 SP4
0.9.13-150400.1.9
fixed
suse enterprise sap 15 SP4
0.9.13-150400.1.9
fixed
suse enterprise server 15 SP4
0.9.13-150400.1.9
fixed
suse enterprise workstation 15 SP4
0.9.13-150400.1.9
fixed
libvncserver0
suse enterprise desktop 15 SP2
0.9.10-4.14.1
fixed
suse enterprise desktop 15 SP3
0.9.10-4.25.1
fixed
suse enterprise sap 15 SP2
0.9.10-4.14.1
fixed
suse enterprise sap 15 SP3
0.9.10-4.25.1
fixed
suse enterprise server 15 SP2
0.9.10-4.14.1
fixed
suse enterprise server 15 SP3
0.9.10-4.25.1
fixed
suse enterprise workstation 15 SP2
0.9.10-4.14.1
fixed
suse enterprise workstation 15 SP3
0.9.10-4.25.1
fixed
libvncserver1
suse enterprise desktop 15 SP4
0.9.13-150400.1.9
fixed
suse enterprise sap 15 SP4
0.9.13-150400.1.9
fixed
suse enterprise server 15 SP4
0.9.13-150400.1.9
fixed
suse enterprise workstation 15 SP4
0.9.13-150400.1.9
fixed
lzo-devel
suse enterprise desktop 15
2.10-2.22
fixed
suse enterprise desktop 15 SP1
2.10-2.22
fixed
suse enterprise desktop 15 SP2
2.10-2.22
fixed
suse enterprise desktop 15 SP3
2.10-2.22
fixed
suse enterprise desktop 15 SP4
2.10-2.22
fixed
suse enterprise desktop 15 SP5
2.10-2.22
fixed
suse enterprise desktop 15 SP6
2.10-2.22
fixed
suse enterprise desktop 15 SP7
2.10-2.22
fixed
suse enterprise sap 15
2.10-2.22
fixed
suse enterprise sap 15 SP1
2.10-2.22
fixed
suse enterprise sap 15 SP2
2.10-2.22
fixed
suse enterprise sap 15 SP3
2.10-2.22
fixed
suse enterprise sap 15 SP4
2.10-2.22
fixed
suse enterprise sap 15 SP5
2.10-2.22
fixed
suse enterprise sap 15 SP6
2.10-2.22
fixed
suse enterprise sap 15 SP7
2.10-2.22
fixed
suse enterprise server 15
2.10-2.22
fixed
suse enterprise server 15 SP1
2.10-2.22
fixed
suse enterprise server 15 SP2
2.10-2.22
fixed
suse enterprise server 15 SP3
2.10-2.22
fixed
suse enterprise server 15 SP4
2.10-2.22
fixed
suse enterprise server 15 SP5
2.10-2.22
fixed
suse enterprise server 15 SP6
2.10-2.22
fixed
suse enterprise server 15 SP7
2.10-2.22
fixed
lzo-devel-static
suse enterprise desktop 15
2.10-2.22
fixed
suse enterprise desktop 15 SP1
2.10-2.22
fixed
suse enterprise desktop 15 SP2
2.10-2.22
fixed
suse enterprise desktop 15 SP3
2.10-2.22
fixed
suse enterprise desktop 15 SP4
2.10-2.22
fixed
suse enterprise desktop 15 SP5
2.10-2.22
fixed
suse enterprise desktop 15 SP6
2.10-2.22
fixed
suse enterprise desktop 15 SP7
2.10-2.22
fixed
suse enterprise sap 15
2.10-2.22
fixed
suse enterprise sap 15 SP1
2.10-2.22
fixed
suse enterprise sap 15 SP2
2.10-2.22
fixed
suse enterprise sap 15 SP3
2.10-2.22
fixed
suse enterprise sap 15 SP4
2.10-2.22
fixed
suse enterprise sap 15 SP5
2.10-2.22
fixed
suse enterprise sap 15 SP6
2.10-2.22
fixed
suse enterprise sap 15 SP7
2.10-2.22
fixed
suse enterprise server 15
2.10-2.22
fixed
suse enterprise server 15 SP1
2.10-2.22
fixed
suse enterprise server 15 SP2
2.10-2.22
fixed
suse enterprise server 15 SP3
2.10-2.22
fixed
suse enterprise server 15 SP4
2.10-2.22
fixed
suse enterprise server 15 SP5
2.10-2.22
fixed
suse enterprise server 15 SP6
2.10-2.22
fixed
suse enterprise server 15 SP7
2.10-2.22
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
lzo
RHEL 6
0:2.03-3.1.el6_5.1
fixed
RHEL 7
0:2.06-6.el7_0.2
fixed
lzo-devel
RHEL 6
0:2.03-3.1.el6_5.1
fixed
RHEL 7
0:2.06-6.el7_0.2
fixed
lzo-minilzo
RHEL 6
0:2.03-3.1.el6_5.1
fixed
RHEL 7
0:2.06-6.el7_0.2
fixed