CVE-2014-4610
published 2020-01-14CVE-2014-4610: Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.10.14, 1.1.x before 1.1.12, 1.2.x before 1.2.7, 2.0.x before 2.0.5, 2.1.x before…
PriorityP350high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
4.47%
90.4th percentile
Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.10.14, 1.1.x before 1.1.12, 1.2.x before 1.2.7, 2.0.x before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.4 allows remote attackers to execute arbitrary code via a crafted Literal Run.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:2.4.1-1 (bookworm) | ffmpeg 7:2.4.1-1 (bookworm) |
| ffmpeg | ffmpeg | < 0.10.14 | 0.10.14 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 1.1 < 1.1.12 | 1.1.12 |
| ffmpeg | ffmpeg | >= 1.2 < 1.2.7 | 1.2.7 |
| ffmpeg | ffmpeg | >= 2.0 < 2.0.5 | 2.0.5 |
| ffmpeg | ffmpeg | >= 2.1 < 2.1.5 | 2.1.5 |
| ffmpeg | ffmpeg | >= 2.2 < 2.2.4 | 2.2.4 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ffmpeg: av_lzo1x_decode() integer overflow
vendor_redhat·2014-06-26·CVSS 8.8
CVE-2014-4610 [HIGH] CWE-190 ffmpeg: av_lzo1x_decode() integer overflow
ffmpeg: av_lzo1x_decode() integer overflow
Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.10.14, 1.1.x before 1.1.12, 1.2.x before 1.2.7, 2.0.x before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.4 allows remote attackers to execute arbitrary code via a crafted Literal Run.
Statement: Not vulnerable. This issue does not affect the version of qffmpeg as shipped with Red Hat Enterprise Linux 5. This issue does not affect the version of gstreamer-plugins-good as shipped with Red Hat Enterprise Linux 5, 6 and 7. This issue does not affect the version of gstreamer1-plugins-good as shipped with Red Hat Enterprise Linux 7.
Package: gstreamer-plugins-good (Red Hat Enterprise Linux 5) - Not affected
Package: qffmpeg (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2014-4610: ffmpeg - Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.1...
vendor_debian·2014·CVSS 8.8
CVE-2014-4610 [HIGH] CVE-2014-4610: ffmpeg - Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.1...
Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.10.14, 1.1.x before 1.1.12, 1.2.x before 1.2.7, 2.0.x before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.4 allows remote attackers to execute arbitrary code via a crafted Literal Run.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
GHSA
GHSA-5mj4-fmj2-m24x: Integer overflow in the get_len function in libavutil/lzo
ghsa_unreviewed·2022-05-17
CVE-2014-4610 [HIGH] CWE-190 GHSA-5mj4-fmj2-m24x: Integer overflow in the get_len function in libavutil/lzo
Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.10.14, 1.1.x before 1.1.12, 1.2.x before 1.2.7, 2.0.x before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.4 allows remote attackers to execute arbitrary code via a crafted Literal Run.
OSV
CVE-2014-4610: Integer overflow in the get_len function in libavutil/lzo
osv·2020-01-14·CVSS 8.8
CVE-2014-4610 [HIGH] CVE-2014-4610: Integer overflow in the get_len function in libavutil/lzo
Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.10.14, 1.1.x before 1.1.12, 1.2.x before 1.2.7, 2.0.x before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.4 allows remote attackers to execute arbitrary code via a crafted Literal Run.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-4610 gstreamer-plugins-good: ffmpeg LZO: LZ4_decompress_generic() integer overflow [fedora-all]
bugzilla·2014-06-27·CVSS 8.8
CVE-2014-4610 [HIGH] CVE-2014-4610 gstreamer-plugins-good: ffmpeg LZO: LZ4_decompress_generic() integer overflow [fedora-all]
CVE-2014-4610 gstreamer-plugins-good: ffmpeg LZO: LZ4_decompress_generic() integer overflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: t
Bugzilla
CVE-2014-4610 ffmpeg: av_lzo1x_decode() integer overflow
bugzilla·2014-06-24·CVSS 8.8
CVE-2014-4610 [HIGH] CVE-2014-4610 ffmpeg: av_lzo1x_decode() integer overflow
CVE-2014-4610 ffmpeg: av_lzo1x_decode() integer overflow
Don A. Bailey of securitymouse.com reports:
Vulnerability Description
An integer overflow can occur when processing any variant of a "literal run"
in the av_lzo1x_decode function. Each of these three locations is
subject to an integer overflow when processing zero bytes.
Due to flaws in multiple functions within the libav code base, various
checks can be bypassed that allow for corruption of precise locations in
memory.
This issue is LAZARUS.4
Discussion:
Please note that gstreamer-plugins-good contains an embedded copy of lzo.c from ffmpeg:
commit c4912dac78c8d47e9c980ff74ceea667434ff764
Author: Sebastian Dröge
Date: Sat Aug 2 18:18:05 2008 +0000
Decode the codec private data and following ContentEncoding if
necessary.
Orig
http://blog.securitymouse.com/2014/06/raising-lazarus-20-year-old-bug-that.htmlhttp://www.openwall.com/lists/oss-security/2014/06/26/23https://www.ffmpeg.org/security.htmlhttp://blog.securitymouse.com/2014/06/raising-lazarus-20-year-old-bug-that.htmlhttp://www.openwall.com/lists/oss-security/2014/06/26/23https://www.ffmpeg.org/security.html
2020-01-14
Published