cbcvebase.
CVE-2014-4608
published 2014-07-03

CVE-2014-4608: Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompressor in the Linux kernel before 3.15.2…

high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompressor in the Linux kernel before 3.15.2 allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Literal Run. NOTE: the author of the LZO algorithms says "the Linux kernel is *not* affected; media hype.

Affected

14 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianlinux< linux 3.14.9-1 (bookworm)linux 3.14.9-1 (bookworm)
linuxlinux_kernel< 3.15.23.15.2
linuxlinux_kernel>= 0 < 3.14.9-13.14.9-1
linuxlinux_kernel>= 0 < 3.14.9-13.14.9-1
linuxlinux_kernel>= 0 < 3.14.9-13.14.9-1
linuxlinux_kernel>= 0 < 3.14.9-13.14.9-1
linuxlinux_kernel>= 0 < 3.13.0-40.693.13.0-40.69
opensuseopensuse
suselinux_enterprise_real_time_extension
suselinux_enterprise_server

CVSS provenance

nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
osv7.3HIGH