CVE-2014-4607

EUVD-2014-4534
Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
Affected Products (NVD)
VendorProductVersion
oberhumerliblzo2
𝑥
< 2.07
oberhumerlzo2
𝑥
< 2.07
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
busybox
bookworm
1:1.35.0-4
fixed
bullseye
1:1.30.1-6
fixed
sid
1:1.37.0-4
fixed
squeeze
no-dsa
trixie
1:1.37.0-4
fixed
wheezy
no-dsa
lzo2
bookworm
2.10-2
fixed
bullseye
2.10-2
fixed
sid
2.10-3
fixed
squeeze
no-dsa
trixie
2.10-3
fixed
wheezy
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
grub2
bionic
not-affected
focal
Fixed 2.04-1ubuntu26.8
released
groovy
Fixed 2.04-1ubuntu35.2
released
hirsute
Fixed 2.04-1ubuntu37
released
impish
Fixed 2.04-1ubuntu37
released
jammy
Fixed 2.04-1ubuntu37
released
kinetic
Fixed 2.04-1ubuntu37
released
lunar
Fixed 2.04-1ubuntu37
released
mantic
Fixed 2.04-1ubuntu37
released
noble
Fixed 2.04-1ubuntu37
released
trusty
not-affected
xenial
not-affected
grub2-signed
bionic
not-affected
focal
Fixed 1.142.10
released
groovy
Fixed 1.155.2
released
hirsute
Fixed 1.157
released
impish
Fixed 1.157
released
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
not-affected
xenial
not-affected
grub2-unsigned
bionic
not-affected
focal
Fixed 2.04-1ubuntu47.4
released
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
dne
xenial
not-affected
krfb
bionic
Fixed 4:4.13.97-0ubuntu2
released
focal
Fixed 4:4.13.97-0ubuntu2
released
groovy
Fixed 4:4.13.97-0ubuntu2
released
hirsute
Fixed 4:4.13.97-0ubuntu2
released
impish
Fixed 4:4.13.97-0ubuntu2
released
jammy
Fixed 4:4.13.97-0ubuntu2
released
kinetic
Fixed 4:4.13.97-0ubuntu2
released
lucid
dne
lunar
Fixed 4:4.13.97-0ubuntu2
released
mantic
Fixed 4:4.13.97-0ubuntu2
released
noble
Fixed 4:4.13.97-0ubuntu2
released
precise
dne
trusty
Fixed 4:4.13.0-0ubuntu1.1
released
xenial
Fixed 4:4.13.97-0ubuntu2
released
lzo2
bionic
Fixed 2.06-1.2ubuntu2
released
focal
Fixed 2.06-1.2ubuntu2
released
groovy
Fixed 2.06-1.2ubuntu2
released
hirsute
Fixed 2.06-1.2ubuntu2
released
impish
Fixed 2.06-1.2ubuntu2
released
jammy
Fixed 2.06-1.2ubuntu2
released
kinetic
Fixed 2.06-1.2ubuntu2
released
lucid
ignored
lunar
Fixed 2.06-1.2ubuntu2
released
mantic
Fixed 2.06-1.2ubuntu2
released
noble
Fixed 2.06-1.2ubuntu2
released
precise
Fixed 2.06-1ubuntu0.1
released
saucy
ignored
trusty
Fixed 2.06-1.2ubuntu1.1
released
xenial
Fixed 2.06-1.2ubuntu2
released