Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Scientific Linux 6: SLSA-2014:0861-2 Moderate: LZO Integer Overflow Risk

Scientific Large Esm H446
Moderate: lzo security update
Date: Wed, 9 Jul 2014 18:43:11 +0000
Reply-To: scientific-linux-users@
Sender: Security Errata for Scientific Linux
 
From: Pat Riehecky 
Subject: Security ERRATA Moderate: lzo on SL6.x i386/srpm/x86_64
MIME-Version: 1.0

Synopsis: Moderate: lzo security update
Advisory ID: SLSA-2014:0861-2
Issue Date: 2014-07-09
CVE Numbers: CVE-2014-4607
--

An integer overflow flaw was found in the way the lzo library decompressed
certain archives compressed with the LZO algorithm. An attacker could
create a specially crafted LZO-compressed input that, when decompressed by
an application using the lzo library, would cause that application to
crash or, potentially, execute arbitrary code. (CVE-2014-4607)

For the update to take effect, all services linked to the lzo library must
be restarted or the system rebooted.
--

SL6
 x86_64
 lzo-2.03-3.1.el6_5.1.i686.rpm
 lzo-devel-2.03-3.1.el6_5.1.i686.rpm
 lzo-2.03-3.1.el6_5.1.x86_64.rpm
 lzo-minilzo-2.03-3.1.el6_5.1.x86_64.rpm
 lzo-devel-2.03-3.1.el6_5.1.x86_64.rpm
 lzo-minilzo-2.03-3.1.el6_5.1.i686.rpm
 lzo-debuginfo-2.03-3.1.el6_5.1.x86_64.rpm
 lzo-debuginfo-2.03-3.1.el6_5.1.i686.rpm
 i386
 lzo-minilzo-2.03-3.1.el6_5.1.i686.rpm
 lzo-2.03-3.1.el6_5.1.i686.rpm
 lzo-devel-2.03-3.1.el6_5.1.i686.rpm
 lzo-debuginfo-2.03-3.1.el6_5.1.i686.rpm
 srpm
 lzo-2.03-3.1.el6_5.1.src.rpm
 noarch
 lzo-debuginfo-2.03-3.1.el6_5.1.i686.rpm
 lzo-debuginfo-2.03-3.1.el6_5.1.x86_64.rpm

- Scientific Linux Development Team