CVE-2014-4609: Libav
High severity, CVSS 8.8. EPSS: 5.7% chance of exploitation in the next 30 days.
Integer overflow in the get_len function in libavutil/lzo.c in Libav before 0.8.13, 9.x before 9.14, and 10.x before 10.2 allows remote attackers to execute arbitrary code via a crafted Literal Run.
Affected products
- Libav Libav: before 0.8.13 (fixed in 0.8.13); from 9.0, before 9.14 (fixed in 9.14); from 10.0, before 10.2 (fixed in 10.2)
Published 2020-01-14. Last modified 2026-06-17.