PT-2017-3119 · Icu+2 · International Components For Unicode (Icu) For C/C+++2

Publicado

2017-09-08

·

Atualizado

2019-04-23

·

CVE-2017-14952

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions International Components for Unicode (ICU) for C/C++ versions through 59.1
Description The issue is related to a double free in the i18n/zonemeta.cpp component, which can be exploited by remote attackers to execute arbitrary code via a crafted string. This is due to a redundant UVector entry clean up function call.
Recommendations For International Components for Unicode (ICU) for C/C++ versions through 59.1, consider updating to a version that fixes the double free issue in the i18n/zonemeta.cpp component to prevent remote code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Double Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02519
CVE-2017-14952
MGASA-2017-0411
OPENSUSE-SU-2018_1422-1
SUSE-SU-2018:1401-1
SUSE-SU-2018:1401-2
SUSE-SU-2018:1602-1
USN-3458-1
USN-3458-2

Produtos afetados

International Components For Unicode (Icu) For C/C++
Suse
Ubuntu