First published: Fri Jun 27 2014(Updated: )
** DISPUTED ** Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompressor in the Linux kernel before 3.15.2 allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Literal Run. NOTE: the author of the LZO algorithms says "the Linux kernel is *not* affected; media hype."
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | <3.15.2 | |
openSUSE | =11.4 | |
SUSE Linux Enterprise Real Time Extension | =11-sp3 | |
SUSE Linux Enterprise Server | =11-sp2 | |
Ubuntu Linux | =10.04 | |
Ubuntu Linux | =12.04 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =14.10 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.119-1 6.12.11-1 6.12.12-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4608 has a severity rating that indicates a potential denial of service due to memory corruption vulnerabilities.
To fix CVE-2014-4608, update to a version of the Linux kernel that is 3.15.2 or higher, or apply relevant patches provided by your distribution.
CVE-2014-4608 affects multiple versions of the Linux kernel and distributions like openSUSE, SUSE Linux Enterprise, and Ubuntu.
Context-dependent attackers are able to exploit CVE-2014-4608 by crafting specific LZO decompression inputs.
CVE-2014-4608 is classified as an integer overflow vulnerability leading to memory corruption.