Описание
Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.
An integer overflow flaw was found in the way the lzo library decompressed certain archives compressed with the LZO algorithm. An attacker could create a specially crafted LZO-compressed input that, when decompressed by an application using the lzo library, would cause that application to crash or, potentially, execute arbitrary code.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | busybox | Will not fix | ||
| Red Hat Enterprise Linux 5 | dump | Will not fix | ||
| Red Hat Enterprise Linux 5 | gnutls | Not affected | ||
| Red Hat Enterprise Linux 6 | busybox | Will not fix | ||
| Red Hat Enterprise Linux 6 | dump | Will not fix | ||
| Red Hat Enterprise Linux 6 | kdenetwork | Under investigation | ||
| Red Hat Enterprise Linux 7 | dump | Will not fix | ||
| Red Hat Enterprise Linux 7 | grub2 | Under investigation | ||
| Red Hat Enterprise Linux 7 | kdenetwork | Under investigation | ||
| Red Hat Enterprise Linux 6 | lzo | Fixed | RHSA-2014:0861 | 09.07.2014 |
Показывать по
Дополнительная информация
Статус:
5.1 Medium
CVSS2
Связанные уязвимости
Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.
Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.
Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.
Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and ...
Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.
5.1 Medium
CVSS2