cbcvebase.
CVE-2014-4715
published 2014-07-03

CVE-2014-4715: Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows, which…

PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.75%
84.5th percentile
Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows, which allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run, a different vulnerability than CVE-2014-4611.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.14.9-1 (bookworm)linux 3.14.9-1 (bookworm)
debianlz4< lz4 0.0~r119-1 (bookworm)lz4 0.0~r119-1 (bookworm)
debianlz4< linux 3.14.9-1 (bookworm)linux 3.14.9-1 (bookworm)
linuxlinux_kernel< 3.15.23.15.2
linuxlinux_kernel>= 0 < 3.14.9-13.14.9-1
linuxlinux_kernel>= 0 < 3.14.9-13.14.9-1
linuxlinux_kernel>= 0 < 3.14.9-13.14.9-1
linuxlinux_kernel>= 0 < 3.14.9-13.14.9-1
lz4_projectlz4>= 0 < 0.0~r119-10.0~r119-1
lz4_projectlz4>= 0 < 0.0~r119-10.0~r119-1
lz4_projectlz4>= 0 < 0.0~r119-10.0~r119-1
lz4_projectlz4>= 0 < 0.0~r119-10.0~r119-1
yann_colletlz4<= r118

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.