Integer overflow in the get_len function in libavutil/lzo.c in Libav before 0.8.13, 9.x before 9.14, and 10.x before 10.2 allows remote attackers to execute arbitrary code via a crafted Literal Run.
2020-01-14T16:15:11.307
2024-11-21T02:10:33.510
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | libav | libav | < 0.8.13 | Yes |
| Application | libav | libav | < 9.14 | Yes |
| Application | libav | libav | < 10.2 | Yes |