CVE-2014-3776: Call-Cc Chicken

High severity, CVSS 7.5. EPSS: 4.5% chance of exploitation in the next 30 days.

Buffer overflow in the "read-u8vector!" procedure in the srfi-4 unit in CHICKEN stable 4.8.0.7 and development snapshots before 4.9.1 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via a "#f" value in the NUM argument.

Affected products

  • Call-Cc Chicken: up to and including 4.9.0; version 4.8.0.7 only

Published 2014-05-20. Last modified 2026-06-17.