PT-2017-14051 · Google+5 · Google Chrome+5

Yuan Deng

·

Published

2017-10-26

·

Updated

2024-06-15

·

CVE-2017-15396

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions International Components for Unicode (ICU) for C/C++ versions prior to 60.2 Google Chrome versions prior to 62.0.3202.75
Description A stack buffer overflow in the NumberingSystem component allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. This issue affects various products, including Google Chrome, Opera, and others.
Recommendations For International Components for Unicode (ICU) for C/C++ versions prior to 60.2, update to version 60.2 or later. For Google Chrome versions prior to 62.0.3202.75, update to version 62.0.3202.75 or later.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2600
CVE-2017-15396
DSA-4020-1
MGASA-2017-0423
OPENSUSE-SU-2017:3245-1
OPENSUSE-SU-2017_2902-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:12948-1
RHSA-2017:3082
RHSA-2017_3082

Affected Products

Alt Linux
Google Chrome
Icu
Opera
Red Hat
Suse