PT-2011-1024 · Icu+3 · International Components For Unicode+3

Ludwig Nussel

·

Publicado

2011-12-13

·

Atualizado

2023-02-13

·

CVE-2011-4599

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions International Components for Unicode (ICU) versions prior to 49.1
Description The issue is related to a stack-based buffer overflow in the canonicalize function in common/uloc.c that allows remote attackers to execute arbitrary code via a crafted locale ID. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be done remotely.
Recommendations For International Components for Unicode (ICU) versions prior to 49.1, update to version 49.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the canonicalize function in common/uloc.c until a patch is available.

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01745
BDU:2015-07265
BDU:2015-07266
BDU:2015-07339
BDU:2015-07341
BDU:2015-07343
BDU:2015-08808
BDU:2015-08809
BDU:2015-08810
BDU:2015-08811
BDU:2015-08812
BDU:2015-09659
CESA-2011_1815
CVE-2011-4599
DSA-2397-1
RHSA-2011:1815
RHSA-2011_1815
SUSE-SU-2012_0457-1

Produtos afetados

Centos
International Components For Unicode
Red Hat
Suse