libicu in International Components for Unicode (ICU) 3.8.1 and earlier attempts to process backreferences to the nonexistent capture group zero (aka \0), which might allow context-dependent attackers to read from, or write to, out-of-bounds memory locations, related to corruption of REStackFrames.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Openoffice | — | Upgrade Apache OpenOffice to the latest version | Sep 12, 2025 | Jan 28, 2008 |
| Debian | — | Upgrade icu | Jul 30, 2024 | Jan 29, 2008 |
| Gentoo Linux | — | Upgrade app-office/openoffice-bin.Upgrade app-office/openoffice.Upgrade dev-libs/icu. | Oct 30, 2017 | Jan 28, 2008 |
| Oracle_linux | — | Upgrade libicuUpgrade icuUpgrade libicu-develUpgrade libicu-doc | Oct 16, 2024 | Jan 28, 2008 |
| Suse | — | Upgrade libicu77-ledataUpgrade libicu77Upgrade icuUpgrade libicu77-bedataUpgrade libicu-devel-32bitUpgrade libicuUpgrade libicu-32bitUpgrade libicu-docUpgrade libicu-develUpgrade libicu-x86 | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade libicu34Upgrade libicu36 | Nov 8, 2024 | Jan 29, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub