[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3725-1 icu -- icu

ID: oval:org.secpod.oval:def:602684Date: (C)2016-11-28   (M)2024-01-29
Class: PATCHFamily: unix




Several vulnerabilities were discovered in the International Components for Unicode library. CVE-2014-9911 Michele Spagnuolo discovered a buffer overflow vulnerability which might allow remote attackers to cause a denial of service or possibly execute arbitrary code via crafted text. CVE-2015-2632 An integer overflow vulnerability might lead into a denial of service or disclosure of portion of application memory if an attacker has control on the input file. CVE-2015-4844 Buffer overflow vulnerabilities might allow an attacker with control on the font file to perform a denial of service attacker or, possibly, execute arbitrary code. CVE-2016-0494 Integer signedness issues were introduced as part of the CVE-2015-4844 fix. CVE-2016-6293 A buffer overflow might allow an attacker to perform a denial of service or disclosure of portion of application memory. CVE-2016-7415 A stack-based buffer overflow might allow an attacker with control on the locale string to perform a denial of service and, possibly, execute arbitrary code.

Platform:
Debian 8.x
Product:
libicu52
Reference:
DSA-3725-1
CVE-2014-9911
CVE-2015-2632
CVE-2015-4844
CVE-2016-0494
CVE-2016-6293
CVE-2016-7415
CVE    6
CVE-2016-7415
CVE-2014-9911
CVE-2016-0494
CVE-2015-4844
...
CPE    2
cpe:/o:debian:debian_linux:8.x
cpe:/a:icu_project:libicu:52

© SecPod Technologies