ubuntu · CVE-2014-3776

Quick triage

Priority: medium Published: 2014-05-20 14:55:00 UTC Updated: 2024-07-24 15:57:39 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2014-3776 medium priority: Ubuntu including 1 source packages (chicken), 15 status rows across 15 suites (artful, bionic, cosmic, disco, lucid, precise, saucy, trusty, upstream, utopic, vivid, wily, xenial, yakkety, zesty): not-affected 7, ignored 6, DNE 1, needs-triage 1.

Description:

Buffer overflow in the "read-u8vector!" procedure in the srfi-4 unit in CHICKEN stable 4.8.0.7 and development snapshots before 4.9.1 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via a "#f" value in the NUM argument.

cvelogic Threat Intelligence