Candidate: CVE-2014-4610 PublicDate: 2020-01-14 16:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4610 http://www.securitymouse.com/lms-2014-06-16-4/ Description: Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.10.14, 1.1.x before 1.1.12, 1.2.x before 1.2.7, 2.0.x before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.4 allows remote attackers to execute arbitrary code via a crafted Literal Run. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_ffmpeg: upstream: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=d6af26c55c1ea30f85a7d9edbc373f53be1743ee upstream: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=cf2b7c01f81c1fb3283a1390c0ca9a2f81f4f4a8 upstream_ffmpeg: released (7:2.4.1-1) precise_ffmpeg: DNE precise/esm_ffmpeg: DNE trusty_ffmpeg: DNE trusty/esm_ffmpeg: DNE vivid_ffmpeg: not-affected (7:2.5.8-0ubuntu0.15.04.1) vivid/stable-phone-overlay_ffmpeg: DNE vivid/ubuntu-core_ffmpeg: DNE wily_ffmpeg: not-affected xenial_ffmpeg: not-affected yakkety_ffmpeg: not-affected zesty_ffmpeg: not-affected artful_ffmpeg: not-affected bionic_ffmpeg: not-affected devel_ffmpeg: not-affected Patches_libav: upstream: https://git.libav.org/?p=libav.git;a=commit;h=ccda51b14c0fcae2fad73a24872dce75a7964996 upstream_libav: needs-triage precise_libav: not-affected (4:0.8.17-0ubuntu0.12.04.1) precise/esm_libav: DNE (precise was not-affected [4:0.8.17-0ubuntu0.12.04.1]) trusty_libav: not-affected trusty/esm_libav: DNE (trusty was not-affected) vivid_libav: ignored (reached end-of-life) vivid/stable-phone-overlay_libav: DNE vivid/ubuntu-core_libav: DNE wily_libav: DNE xenial_libav: DNE yakkety_libav: DNE zesty_libav: DNE artful_libav: DNE bionic_libav: DNE devel_libav: DNE