Raising Lazarus – The 20 Year Old Bug that Went to Mars
blog.securitymouse.com
blog.securitymouse.com
It's likely that anything you use that decompresses LZO (MPEG files are a good example) uses C code to do it, and not code in a higher-level language.
So you'd want to know any place your application accepts a file format that can use LZO, because that might be a potential memory corruption flaw in your application regardless of the language you built it in.
Memory corruption flaws are very bad; these are the bugs that often result in attackers being able to upload code to your server that is then executed. That vulnerability, once triggered on your site, is probably game-over for your whole data center/deployment environment.
This flaw won't be as easy to exploit as the Rails YAML bug will be, but to the extent that your code reuses a well-known LZO codec, there may be shrink-wrap exploits available soon.
http://fastcompression.blogspot.com/2014/06/debunking-lz4-20...