Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2014-4607

Published: 9 July 2014

Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.

Notes

AuthorNote
alexmurray
grub2 has a vendored copy of minilzo which is part of lzo2 so likely any vulnerabilities that affect lzo2 may also affect minilzo in grub2 and hence grub2-signed
mdeslaur
grub2 since bug 1911440 now pulls in the system lzo2 when
building, so focal+ is fixed
grub2-signed on bionic now ships the grub binary built on a
later release, so it is not vulnerable to this CVE

Priority

Medium

Cvss 3 Severity Score

8.8

Score breakdown

Status

Package Release Status
grub2
Launchpad, Ubuntu, Debian
bionic Not vulnerable
(does not affect Secure Boot)
focal
Released (2.04-1ubuntu26.8)
groovy
Released (2.04-1ubuntu35.2)
hirsute
Released (2.04-1ubuntu37)
impish
Released (2.04-1ubuntu37)
jammy
Released (2.04-1ubuntu37)
kinetic
Released (2.04-1ubuntu37)
lunar
Released (2.04-1ubuntu37)
mantic
Released (2.04-1ubuntu37)
trusty Not vulnerable
(does not affect Secure Boot)
upstream Needs triage

xenial Not vulnerable
(does not affect Secure Boot)
Patches:
upstream: https://github.com/rhboot/grub2/commit/934e762c46d118b52d8e6a4817c3bca751cb2eeb
upstream: https://git.savannah.gnu.org/cgit/grub.git/commit/?id=3165efcfc24dab1cad5a5c2f5e7578bd876e6b52
grub2-signed
Launchpad, Ubuntu, Debian
bionic Not vulnerable
(code not present)
focal
Released (1.142.10)
groovy
Released (1.155.2)
hirsute
Released (1.157)
impish
Released (1.157)
jammy Not vulnerable
(1.180)
kinetic Not vulnerable
(1.185)
lunar Not vulnerable
(1.192)
mantic Not vulnerable
(1.193)
trusty Not vulnerable
(code not present)
upstream Needs triage

xenial Not vulnerable
(code not present)
grub2-unsigned
Launchpad, Ubuntu, Debian
bionic Not vulnerable
(code not present)
focal
Released (2.04-1ubuntu47.4)
jammy Not vulnerable
(2.06-2ubuntu7)
kinetic Not vulnerable
(2.06-2ubuntu12)
lunar Not vulnerable
(2.06-2ubuntu16)
mantic Not vulnerable
(2.06-2ubuntu17)
trusty Does not exist

upstream Not vulnerable
(code not present)
xenial Not vulnerable
(code not present)
krfb
Launchpad, Ubuntu, Debian
bionic
Released (4:4.13.97-0ubuntu2)
focal
Released (4:4.13.97-0ubuntu2)
groovy
Released (4:4.13.97-0ubuntu2)
hirsute
Released (4:4.13.97-0ubuntu2)
impish
Released (4:4.13.97-0ubuntu2)
jammy
Released (4:4.13.97-0ubuntu2)
kinetic
Released (4:4.13.97-0ubuntu2)
lucid Does not exist

lunar
Released (4:4.13.97-0ubuntu2)
mantic
Released (4:4.13.97-0ubuntu2)
precise Does not exist

trusty
Released (4:4.13.0-0ubuntu1.1)
upstream
Released (4.14)
xenial
Released (4:4.13.97-0ubuntu2)
lzo2
Launchpad, Ubuntu, Debian
bionic
Released (2.06-1.2ubuntu2)
focal
Released (2.06-1.2ubuntu2)
groovy
Released (2.06-1.2ubuntu2)
hirsute
Released (2.06-1.2ubuntu2)
impish
Released (2.06-1.2ubuntu2)
jammy
Released (2.06-1.2ubuntu2)
kinetic
Released (2.06-1.2ubuntu2)
lucid Ignored
(end of life)
lunar
Released (2.06-1.2ubuntu2)
mantic
Released (2.06-1.2ubuntu2)
precise
Released (2.06-1ubuntu0.1)
saucy Ignored
(end of life)
trusty
Released (2.06-1.2ubuntu1.1)
upstream Needs triage

xenial
Released (2.06-1.2ubuntu2)

Severity score breakdown

Parameter Value
Base score 8.8
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H