← Back

CVE-2014-4610

nvd nist
Published: Jan 14, 2020Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.10.14, 1.1.x before 1.1.12, 1.2.x before 1.2.7, 2.0.x before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.4 allows remote attackers to execute arbitrary code via a crafted Literal Run.

Affected (6)

Products: Ffmpeg: Ffmpeg
1 product
Ffmpeg
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Ffmpeg
Before 0.10.14
From 1.1 to 1.1.12
From 1.2 to 1.2.7
From 2.0 to 2.0.5
From 2.1 to 2.1.5
From 2.2 to 2.2.4

References (6)

Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.