CVE-2014-4715
published 2014-07-03CVE-2014-4715: Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows, which…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.75%
84.5th percentile
Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows, which allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run, a different vulnerability than CVE-2014-4611.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.14.9-1 (bookworm) | linux 3.14.9-1 (bookworm) |
| debian | lz4 | < lz4 0.0~r119-1 (bookworm) | lz4 0.0~r119-1 (bookworm) |
| debian | lz4 | < linux 3.14.9-1 (bookworm) | linux 3.14.9-1 (bookworm) |
| linux | linux_kernel | < 3.15.2 | 3.15.2 |
| linux | linux_kernel | >= 0 < 3.14.9-1 | 3.14.9-1 |
| linux | linux_kernel | >= 0 < 3.14.9-1 | 3.14.9-1 |
| linux | linux_kernel | >= 0 < 3.14.9-1 | 3.14.9-1 |
| linux | linux_kernel | >= 0 < 3.14.9-1 | 3.14.9-1 |
| lz4_project | lz4 | >= 0 < 0.0~r119-1 | 0.0~r119-1 |
| lz4_project | lz4 | >= 0 < 0.0~r119-1 | 0.0~r119-1 |
| lz4_project | lz4 | >= 0 < 0.0~r119-1 | 0.0~r119-1 |
| lz4_project | lz4 | >= 0 < 0.0~r119-1 | 0.0~r119-1 |
| yann_collet | lz4 | <= r118 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c356-gp5w-pv9x: Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows,
ghsa_unreviewed·2022-05-17·CVSS 5.0
CVE-2014-4715 [MEDIUM] GHSA-c356-gp5w-pv9x: Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows,
Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows, which allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run, a different vulnerability than CVE-2014-4611.
GHSA
GHSA-c7c4-fwj7-36pr: Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompr
ghsa_unreviewed·2022-05-13·CVSS 5.0
CVE-2014-4611 [MEDIUM] CWE-20 GHSA-c7c4-fwj7-36pr: Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompr
Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompress.c in the Linux kernel before 3.15.2, on 32-bit platforms might allow context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run that would be improperly handled by programs not complying with an API limitation, a different vulnerability than CVE-2014-4715.
OSV
CVE-2014-4715: Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows,
osv·2014-07-03·CVSS 5.0
CVE-2014-4715 [MEDIUM] CVE-2014-4715: Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows,
Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows, which allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run, a different vulnerability than CVE-2014-4611.
OSV
CVE-2014-4611: Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompr
osv·2014-07-03·CVSS 5.0
CVE-2014-4611 [MEDIUM] CVE-2014-4611: Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompr
Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompress.c in the Linux kernel before 3.15.2, on 32-bit platforms might allow context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run that would be improperly handled by programs not complying with an API limitation, a different vulnerability than CVE-2014-4715.
Red Hat
lz4: LZ4_decompress_generic() integer overflow (32-bit arches)
vendor_redhat·2014-07-03·CVSS 5.0
CVE-2014-4715 [MEDIUM] CWE-190 lz4: LZ4_decompress_generic() integer overflow (32-bit arches)
lz4: LZ4_decompress_generic() integer overflow (32-bit arches)
Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows, which allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run, a different vulnerability than CVE-2014-4611.
Statement: This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: realtime-kernel (Red Hat Enterpris
Red Hat
lz4: LZ4_decompress_generic() integer overflow
vendor_redhat·2014-06-26·CVSS 5.0
CVE-2014-4611 [MEDIUM] CWE-190 lz4: LZ4_decompress_generic() integer overflow
lz4: LZ4_decompress_generic() integer overflow
Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompress.c in the Linux kernel before 3.15.2, on 32-bit platforms might allow context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run that would be improperly handled by programs not complying with an API limitation, a different vulnerability than CVE-2014-4715.
Statement: Not vulnerable. This issue does not affect the kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise Linux MRG 2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterpri
Debian
CVE-2014-4715: lz4 - Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate...
vendor_debian·2014·CVSS 5.0
CVE-2014-4715 [MEDIUM] CVE-2014-4715: lz4 - Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate...
Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows, which allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run, a different vulnerability than CVE-2014-4611.
Scope: local
bookworm: resolved (fixed in 0.0~r119-1)
bullseye: resolved (fixed in 0.0~r119-1)
forky: resolved (fixed in 0.0~r119-1)
sid: resolved (fixed in 0.0~r119-1)
trixie: resolved (fixed in 0.0~r119-1)
Debian
CVE-2014-4611: linux - Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4...
vendor_debian·2014·CVSS 5.0
CVE-2014-4611 [MEDIUM] CVE-2014-4611: linux - Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4...
Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompress.c in the Linux kernel before 3.15.2, on 32-bit platforms might allow context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run that would be improperly handled by programs not complying with an API limitation, a different vulnerability than CVE-2014-4715.
Scope: local
bookworm: resolved (fixed in 3.14.9-1)
bullseye: resolved (fixed in 3.14.9-1)
forky: resolved (fixed in 3.14.9-1)
sid: resolved (fixed in 3.14.9-1)
trixie: resolved (fixed in 3.14.9-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-4715 kernel: lz4: LZ4_decompress_generic() integer overflow (32-bit arches) [fedora-all]
bugzilla·2014-07-04·CVSS 5.0
CVE-2014-4715 [MEDIUM] CVE-2014-4715 kernel: lz4: LZ4_decompress_generic() integer overflow (32-bit arches) [fedora-all]
CVE-2014-4715 kernel: lz4: LZ4_decompress_generic() integer overflow (32-bit arches) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this iss
Bugzilla
CVE-2014-4715 lz4: LZ4_decompress_generic() integer overflow (32-bit arches)
bugzilla·2014-07-03·CVSS 5.0
CVE-2014-4715 [MEDIUM] CVE-2014-4715 lz4: LZ4_decompress_generic() integer overflow (32-bit arches)
CVE-2014-4715 lz4: LZ4_decompress_generic() integer overflow (32-bit arches)
Don A. Bailey of Lab Mouse Security reported an integer overflow issue in various implementations of LZO (Lempel–Ziv–Oberhumer) and LZ4 compression algorithms. The issue is in the handling of "literal runs" during decompression, and can lead to application crash and, possibly, code execution.
The CVE-2014-4715 assignment, from the perspective of the LZ4 product, is for issue 134 fixed in r119:
https://code.google.com/p/lz4/issues/detail?id=134
https://code.google.com/p/lz4/source/detail?r=119
Discussion:
Upstream kernel fix:
-> https://git.kernel.org/linus/4a3a99045177369700c60d074c0e525e8093b0fc
---
Statement:
This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise
http://blog.securitymouse.com/2014/07/i-was-wrong-proving-lz4-exploitable.htmlhttp://fastcompression.blogspot.fr/2014/07/software-vulnerabilities-how-it-works.htmlhttp://secunia.com/advisories/59770https://code.google.com/p/lz4/issues/detail?id=134https://code.google.com/p/lz4/source/detail?r=119http://blog.securitymouse.com/2014/07/i-was-wrong-proving-lz4-exploitable.htmlhttp://fastcompression.blogspot.fr/2014/07/software-vulnerabilities-how-it-works.htmlhttp://secunia.com/advisories/59770https://code.google.com/p/lz4/issues/detail?id=134https://code.google.com/p/lz4/source/detail?r=119
2014-07-03
Published