UBUNTU-CVE-2014-4607

Source
https://ubuntu.com/security/CVE-2014-4607
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-4607.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2014-4607
Related
Published
2014-07-09T00:00:00Z
Modified
2024-11-20T12:20:07Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.

References

Affected packages

Ubuntu:14.04:LTS / krfb

Package

Name
krfb
Purl
pkg:deb/ubuntu/krfb?arch=src?distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4:4.13.0-0ubuntu1.1

Affected versions

4:4.*

4:4.11.2-0ubuntu1
4:4.11.80-0ubuntu1
4:4.11.95-0ubuntu1
4:4.11.97-0ubuntu1
4:4.12.0-0ubuntu1
4:4.12.1-0ubuntu1
4:4.12.2-0ubuntu1
4:4.12.3-0ubuntu1
4:4.12.90-0ubuntu1
4:4.12.95-0ubuntu1
4:4.12.97-0ubuntu1
4:4.13.0-0ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "4:4.13.0-0ubuntu1.1",
            "binary_name": "krfb"
        },
        {
            "binary_version": "4:4.13.0-0ubuntu1.1",
            "binary_name": "krfb-dbg"
        }
    ]
}

Ubuntu:14.04:LTS / lzo2

Package

Name
lzo2
Purl
pkg:deb/ubuntu/lzo2?arch=src?distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.06-1.2ubuntu1.1

Affected versions

2.*

2.06-1.2
2.06-1.2ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "2.06-1.2ubuntu1.1",
            "binary_name": "liblzo2-2"
        },
        {
            "binary_version": "2.06-1.2ubuntu1.1",
            "binary_name": "liblzo2-2-udeb"
        },
        {
            "binary_version": "2.06-1.2ubuntu1.1",
            "binary_name": "liblzo2-dev"
        }
    ]
}

Ubuntu:20.04:LTS / grub2

Package

Name
grub2
Purl
pkg:deb/ubuntu/grub2?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.04-1ubuntu26.8

Affected versions

2.*

2.04-1ubuntu12
2.04-1ubuntu13
2.04-1ubuntu14
2.04-1ubuntu16
2.04-1ubuntu18
2.04-1ubuntu20
2.04-1ubuntu21
2.04-1ubuntu22
2.04-1ubuntu23
2.04-1ubuntu24
2.04-1ubuntu25
2.04-1ubuntu26
2.04-1ubuntu26.1
2.04-1ubuntu26.2
2.04-1ubuntu26.3
2.04-1ubuntu26.4
2.04-1ubuntu26.6
2.04-1ubuntu26.7

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-common"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-common-dbgsym"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-coreboot"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-coreboot-bin"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-coreboot-dbg"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-efi"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-efi-amd64"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-efi-amd64-bin"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-efi-amd64-dbg"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-efi-amd64-signed-template"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-efi-arm"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-efi-arm-bin"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-efi-arm-dbg"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-efi-arm64"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-efi-arm64-bin"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-efi-arm64-dbg"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-efi-arm64-signed-template"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-efi-ia32"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-efi-ia32-bin"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-efi-ia32-dbg"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-emu"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-emu-dbg"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-firmware-qemu"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-ieee1275"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-ieee1275-bin"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-ieee1275-bin-dbgsym"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-ieee1275-dbg"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-linuxbios"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-mount-udeb"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-pc"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-pc-bin"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-pc-bin-dbgsym"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-pc-dbg"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-rescue-pc"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-theme-starfield"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-uboot"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-uboot-bin"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-uboot-dbg"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-xen"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-xen-bin"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-xen-dbg"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub-xen-host"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub2"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub2-common"
        },
        {
            "binary_version": "2.04-1ubuntu26.8",
            "binary_name": "grub2-common-dbgsym"
        }
    ]
}

Ubuntu:20.04:LTS / grub2-signed

Package

Name
grub2-signed
Purl
pkg:deb/ubuntu/grub2-signed?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.142.10

Affected versions

1.*

1.128
1.129
1.130
1.131
1.133
1.134
1.135
1.136
1.137
1.138
1.139
1.140
1.141
1.142
1.142.1
1.142.3
1.142.4
1.142.5
1.142.6
1.142.8
1.142.9

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.142.10+2.04-1ubuntu26.8",
            "binary_name": "grub-efi-amd64-signed"
        },
        {
            "binary_version": "1.142.10+2.04-1ubuntu26.8",
            "binary_name": "grub-efi-arm64-signed"
        }
    ]
}

Ubuntu:20.04:LTS / grub2-unsigned

Package

Name
grub2-unsigned
Purl
pkg:deb/ubuntu/grub2-unsigned?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.04-1ubuntu47.4

Affected versions

2.*

2.04-1ubuntu44
2.04-1ubuntu44.2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "2.04-1ubuntu47.4",
            "binary_name": "grub-efi-amd64"
        },
        {
            "binary_version": "2.04-1ubuntu47.4",
            "binary_name": "grub-efi-amd64-bin"
        },
        {
            "binary_version": "2.04-1ubuntu47.4",
            "binary_name": "grub-efi-amd64-dbg"
        },
        {
            "binary_version": "2.04-1ubuntu47.4",
            "binary_name": "grub-efi-arm64"
        },
        {
            "binary_version": "2.04-1ubuntu47.4",
            "binary_name": "grub-efi-arm64-bin"
        },
        {
            "binary_version": "2.04-1ubuntu47.4",
            "binary_name": "grub-efi-arm64-dbg"
        }
    ]
}

Ubuntu:22.04:LTS / grub2-signed

Package

Name
grub2-signed
Purl
pkg:deb/ubuntu/grub2-signed?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.180

Affected versions

1.*

1.173
1.174
1.176
1.177
1.178
1.179

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.180+2.06-2ubuntu7",
            "binary_name": "grub-efi-amd64-signed"
        },
        {
            "binary_version": "1.180+2.06-2ubuntu7",
            "binary_name": "grub-efi-arm64-signed"
        }
    ]
}

Ubuntu:22.04:LTS / grub2-unsigned

Package

Name
grub2-unsigned
Purl
pkg:deb/ubuntu/grub2-unsigned?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.06-2ubuntu7

Affected versions

2.*

2.04-1ubuntu47
2.04-1ubuntu48
2.06-2ubuntu3
2.06-2ubuntu4
2.06-2ubuntu5
2.06-2ubuntu6

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "2.06-2ubuntu7",
            "binary_name": "grub-efi-amd64"
        },
        {
            "binary_version": "2.06-2ubuntu7",
            "binary_name": "grub-efi-amd64-bin"
        },
        {
            "binary_version": "2.06-2ubuntu7",
            "binary_name": "grub-efi-amd64-dbg"
        },
        {
            "binary_version": "2.06-2ubuntu7",
            "binary_name": "grub-efi-arm64"
        },
        {
            "binary_version": "2.06-2ubuntu7",
            "binary_name": "grub-efi-arm64-bin"
        },
        {
            "binary_version": "2.06-2ubuntu7",
            "binary_name": "grub-efi-arm64-dbg"
        }
    ]
}