Oberhumer LZO CVE-2014-4607 Multiple Memory Corruption Vulnerabilities
BID:68213
Info
Oberhumer LZO CVE-2014-4607 Multiple Memory Corruption Vulnerabilities
| Bugtraq ID: | 68213 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-4607 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 26 2014 12:00AM |
| Updated: | Jan 12 2017 04:11AM |
| Credit: | Don A. Bailey |
| Vulnerable: |
Ubuntu Ubuntu Linux 14.04 LTS Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 SuSE SUSE Linux Enterprise Software Development Kit 11 SP3 SuSE SUSE Linux Enterprise Server 11 SP3 for VMware SuSE SUSE Linux Enterprise Server 11 SP3 SuSE SUSE Linux Enterprise Server 10 SP4 LTSS SuSE SUSE Linux Enterprise Server 10 SP3 LTSS SuSE Suse Linux Enterprise Desktop 11 SP3 SuSE Linux Enterprise Server 11 SP2 LTSS SuSE Linux Enterprise Server 11 SP1 LTSS Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server EUS 6.5.z Redhat Enterprise Linux Server AUS 6.5 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop 6 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oberhumer LZO 0 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 IBM SmartCloud Provisioning 2.3 FixPack 1 IBM SmartCloud Provisioning 2.3 IBM SmartCloud Entry 3.2 Appliance fixpack 22 IBM SmartCloud Entry 3.2 Appliance fixpack 21 IBM SmartCloud Entry 3.2 Appliance fix pack 2 IBM SmartCloud Entry 3.2 Appliance fix pack 1 IBM SmartCloud Entry 3.2 IBM SmartCloud Entry 3.1 IBM SmartCloud Entry 2.4 Appliance fix pack 6 IBM SmartCloud Entry 2.4 Appliance fix pack 4 IBM SmartCloud Entry 2.3 Appliance fix pack 6 IBM SmartCloud Entry 2.3 Appliance fix pack 4 IBM SmartCloud Entry 2.2 Appliance fix pack 6 IBM SmartCloud Entry 2.2 Appliance fix pack 4 IBM SmartCloud Entry 2.2 IBM SmartCloud Entry 3.2.0.4 Appliance FP IBM SmartCloud Entry 3.2.0.4 Appliance FP IBM SmartCloud Entry 3.2.0.4 Appliance FP IBM SmartCloud Entry 3.2.0.4 Appliance FP IBM SmartCloud Entry 3.2.0.4 Appliance FP IBM SmartCloud Entry 3.2.0.4 Appliance FP IBM SmartCloud Entry 3.2.0.4 Appliance FP IBM SmartCloud Entry 3.2.0.4 Appliance FP IBM SmartCloud Entry 3.2.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 2.4.0.4 Appliance Fi IBM SmartCloud Entry 2.4.0.4 Appliance Fi IBM SmartCloud Entry 2.4.0.4 Appliance Fi IBM SmartCloud Entry 2.4.0 IBM SmartCloud Entry 2.3.0.4 Appliance Fi IBM SmartCloud Entry 2.3.0.4 Appliance Fi IBM SmartCloud Entry 2.3.0.4 Appliance Fi IBM SmartCloud Entry 2.3.0 IBM SmartCloud Entry 2.2.0.4 Appliance Fi IBM SmartCloud Entry 2.2.0.4 Appliance Fi IBM SmartCloud Entry 2.2.0.4 Appliance Fi IBM Security Network Protection 5.3.3 IBM Security Network Protection 5.3.2 IBM Security Network Protection 5.3.1 IBM Security Network Protection 5.3.2.4 IBM Security Network Protection 5.3.2.3 IBM Security Network Protection 5.3.2.2 IBM Security Network Protection 5.3.2.1 IBM Security Network Protection 5.3.1.9 IBM Security Network Protection 5.3.1.8 IBM Security Network Protection 5.3.1.7 IBM Security Network Protection 5.3.1.6 IBM Security Network Protection 5.3.1.5 IBM Security Network Protection 5.3.1.4 IBM Security Network Protection 5.3.1.3 IBM Security Network Protection 5.3.1.2 IBM Security Network Protection 5.3.1.10 IBM Security Network Protection 5.3.1.1 IBM DataPower Gateway 7.5.2.0 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 6 |
| Not Vulnerable: |
Oberhumer LZO 2.07 IBM Security Network Protection 5.3.3.1 IBM Security Network Protection 5.3.2.5 IBM Security Network Protection 5.3.1.11 |
Discussion
Oberhumer LZO CVE-2014-4607 Multiple Memory Corruption Vulnerabilities
Oberhumer LZO is prone to a multiple memory-corruption vulnerabilities.
An attacker can exploit these issues to crash the affected application, denying service to legitimate users. Due to the nature of these issues, arbitrary code execution may be possible; however, this has not been confirmed.
Oberhumer LZO versions prior to 2.07 are vulnerable.
Oberhumer LZO is prone to a multiple memory-corruption vulnerabilities.
An attacker can exploit these issues to crash the affected application, denying service to legitimate users. Due to the nature of these issues, arbitrary code execution may be possible; however, this has not been confirmed.
Oberhumer LZO versions prior to 2.07 are vulnerable.
Exploit / POC
Oberhumer LZO CVE-2014-4607 Multiple Memory Corruption Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oberhumer LZO CVE-2014-4607 Multiple Memory Corruption Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Oberhumer LZO CVE-2014-4607 Multiple Memory Corruption Vulnerabilities
References:
References:
- LZO Homepage (oberhumer)
- isg3T1024734:Vulnerabilities in Busybox affect IBM SmartCloud Entry (CVE-2014-46 (IBM)
- LMS-2014-06-16-1: Oberhumer LZO (Seclists.org)
- Moderate: lzo security update (Red Hat)
- Security Bulletin: LZO algorithm vulnerability (CVE-2014-4607) as per June, 2014 (IBM)
- swg21990083: Security Bulletin: Vulnerabilities in busybox affect IBM Security N (IBM)
- swg21993006: A busybox vulnerability affects IBM DataPower Gateways (CVE-2014-46 (IBM)