CVE-2014-9765: Buffer Overflow
Published Apr 19, 2016
·Updated
Buffer overflow in the maingetappheader function in xdelta3-main.h in xdelta3 before 3.0.9 allows remote attackers to execute arbitrary code via a crafted input file.
Affected Software
7 affected components
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Debian Debian Linux=7.0
Debian Debian Linux=8.0
xdelta xdelta3<=3.0.8
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Event History
Apr 19, 2016
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9765?
CVE-2014-9765 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2014-9765?
To fix CVE-2014-9765, update xdelta3 to version 3.0.9 or later.
3
Which software is affected by CVE-2014-9765?
CVE-2014-9765 affects xdelta3 versions up to 3.0.8, as well as specific versions of Ubuntu, Debian, and openSUSE.
4
Can CVE-2014-9765 be exploited remotely?
Yes, CVE-2014-9765 can be exploited remotely if a user processes a crafted input file.
5
What are the potential consequences of CVE-2014-9765?
The potential consequences of CVE-2014-9765 include arbitrary code execution, which may lead to system compromise.