PT-2008-6943 · Icu+1 · Libicu38-Dbg+7

Publicado

1970-01-01

·

Atualizado

2024-06-15

·

CVE-2008-1036

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions International Components for Unicode (ICU) library versions prior to 10.5.3 libicu38 versions (affected versions not specified) lib32icu-dev versions (affected versions not specified) lib32icu38 versions (affected versions not specified) icu-doc versions (affected versions not specified) libicu38-dbg versions (affected versions not specified) libicu-dev versions (affected versions not specified)
Description The issue is related to the International Components for Unicode (ICU) library, which omits some invalid character sequences during conversion of some character encodings. This might allow remote attackers to conduct cross-site scripting (XSS) attacks. The vulnerability can be exploited remotely and may lead to disruption of protected information integrity.
Recommendations For International Components for Unicode (ICU) library versions prior to 10.5.3, update to version 10.5.3 or later. For libicu38, lib32icu-dev, lib32icu38, icu-doc, libicu38-dbg, and libicu-dev, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03449
BDU:2015-03450
BDU:2015-03451
BDU:2015-03452
BDU:2015-03453
BDU:2015-03454
CVE-2008-1036
DSA-1762-1
OPENSUSE-SU-2024:10859-1
RHSA-2009:0296
RHSA-2009_0296

Produtos afetados

International Components For Unicode
Red Hat
Icu-Doc
Lib32Icu-Dev
Lib32Icu38
Libicu-Dev
Libicu38
Libicu38-Dbg