PT-2011-1024 · Icu+3 · International Components For Unicode+3

Ludwig Nussel

·

Published

2011-12-13

·

Updated

2023-02-13

·

CVE-2011-4599

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions International Components for Unicode (ICU) versions prior to 49.1
Description The issue is related to a stack-based buffer overflow in the canonicalize function in common/uloc.c that allows remote attackers to execute arbitrary code via a crafted locale ID. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be done remotely.
Recommendations For International Components for Unicode (ICU) versions prior to 49.1, update to version 49.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the canonicalize function in common/uloc.c until a patch is available.

Fix

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2015-01745
BDU:2015-07265
BDU:2015-07266
BDU:2015-07339
BDU:2015-07341
BDU:2015-07343
BDU:2015-08808
BDU:2015-08809
BDU:2015-08810
BDU:2015-08811
BDU:2015-08812
BDU:2015-09659
CESA-2011_1815
CVE-2011-4599
DSA-2397-1
RHSA-2011:1815
RHSA-2011_1815
SUSE-SU-2012_0457-1

Affected Products

Centos
International Components For Unicode
Red Hat
Suse