Buffer overflow in the main_get_appheader function in xdelta3-main.h in xdelta3 before 3.0.9 allows remote attackers to execute arbitrary code via a crafted input file. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9765