Oval Definition:oval:com.ubuntu.bionic:def:201446100000000
Revision Date:2014-12-31Version:1
Title:CVE-2014-4610 on Ubuntu 18.04 LTS (bionic) - medium.
Description:An integer overflow can occur when processing any variant of a "literal run" in the av_lzo1x_decode function. Each of these three locations is subject to an integer overflow when processing zero bytes. . Due to flaws in multiple functions within the libav code base, various checks can be bypassed that allow for corruption of precise locations in memory.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2014-4610
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND Package Information
  • NOT ffmpeg package in bionic, while related to the CVE in some way, is not affected.
  • OR NOT libavcodec-extra package in bionic, while related to the CVE in some way, is not affected.
  • OR NOT libavcodec-extra57 package in bionic, while related to the CVE in some way, is not affected.
  • OR NOT libavcodec57 package in bionic, while related to the CVE in some way, is not affected.
  • OR NOT libavdevice57 package in bionic, while related to the CVE in some way, is not affected.
  • OR NOT libavfilter-extra package in bionic, while related to the CVE in some way, is not affected.
  • OR NOT libavfilter-extra6 package in bionic, while related to the CVE in some way, is not affected.
  • OR NOT libavfilter6 package in bionic, while related to the CVE in some way, is not affected.
  • OR NOT libavformat57 package in bionic, while related to the CVE in some way, is not affected.
  • OR NOT libavresample3 package in bionic, while related to the CVE in some way, is not affected.
  • OR NOT libavutil55 package in bionic, while related to the CVE in some way, is not affected.
  • OR NOT libpostproc54 package in bionic, while related to the CVE in some way, is not affected.
  • OR NOT libswresample2 package in bionic, while related to the CVE in some way, is not affected.
  • OR NOT libswscale4 package in bionic, while related to the CVE in some way, is not affected.
  • BACK