Overview
ICU Project ICU4C library, versions 52 through 54, contains a heap-based buffer overflow and an integer overflow.
Description
The ICU Project describes ICU as "a mature, widely used set of C/C++ and Java libraries providing Unicode and Globalization support for software applications." CWE-122: Heap-based Buffer Overflow - CVE-2014-8146 |
Impact
An attacker may be able to provide input that triggers one or both overflow vulnerabilities, leading to denial of service and the possibility of code execution. |
Solution
Apply an update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 4.4 | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Temporal | 3.4 | E:POC/RL:OF/RC:C |
Environmental | 3.4 | CDP:N/TD:H/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Pedro Ribeiro (pedrib@gmail.com) of Agile Information Security for reporting this vulnerability.
This document was written by Joel Land.
Other Information
CVE IDs: | CVE-2014-8146, CVE-2014-8147 |
Date Public: | 2015-05-04 |
Date First Published: | 2015-05-04 |
Date Last Updated: | 2015-08-03 14:03 UTC |
Document Revision: | 25 |