CVE-2014-4610Integer Overflow or Wraparound in Ffmpeg

Severity
8.8HIGHNVD
EPSS
3.0%
top 13.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 14
Latest updateMay 17

Description

Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.10.14, 1.1.x before 1.1.12, 1.2.x before 1.2.7, 2.0.x before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.4 allows remote attackers to execute arbitrary code via a crafted Literal Run.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDffmpeg/ffmpeg1.11.1.12+5
debiandebian/ffmpeg< ffmpeg 7:2.4.1-1 (bookworm)
Debianffmpeg/ffmpeg< 7:2.4.1-1+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5mj4-fmj2-m24x: Integer overflow in the get_len function in libavutil/lzo2022-05-17
OSV
CVE-2014-4610: Integer overflow in the get_len function in libavutil/lzo2020-01-14

📋Vendor Advisories

2
Red Hat
ffmpeg: av_lzo1x_decode() integer overflow2014-06-26
Debian
CVE-2014-4610: ffmpeg - Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.1...2014

💬Community

2
Bugzilla
CVE-2014-4610 gstreamer-plugins-good: ffmpeg LZO: LZ4_decompress_generic() integer overflow [fedora-all]2014-06-27
Bugzilla
CVE-2014-4610 ffmpeg: av_lzo1x_decode() integer overflow2014-06-24