Loading
Integer overflow in the get_len function in libavutil/lzo.c in Libav before 0.8.13, 9.x before 9.14, and 10.x before 10.2 allows remote attackers to execute arbitrary code via a crafted Literal Run.
Use CWE-190, Libav vendor hub and Libav product page to widen CVE-2014-4609 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-9719, CVE-2020-18778 and CVE-2020-18776 for nearby disclosures in the same product family.