Heap-based buffer overflow in the doInterval function in regexcmp.cpp in libicu in International Components for Unicode (ICU) 3.8.1 and earlier allows context-dependent attackers to cause a denial of service (memory consumption) and possibly have unspecified other impact via a regular expression that writes a large amount of data to the backtracking stack. NOTE: some of these details are obtained from third party information.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Openoffice | — | Upgrade Apache OpenOffice to the latest version | Sep 12, 2025 | Jan 28, 2008 |
| Debian | — | Upgrade icu | Jul 30, 2024 | Jan 29, 2008 |
| Gentoo Linux | — | Upgrade dev-libs/icu.Upgrade app-office/openoffice-bin.Upgrade app-office/openoffice. | Oct 30, 2017 | Jan 28, 2008 |
| Oracle_linux | — | Upgrade libicu-develUpgrade libicu-docUpgrade icuUpgrade libicu | Oct 16, 2024 | Jan 28, 2008 |
| Suse | — | Upgrade libicuUpgrade libicu77-bedataUpgrade libicu77-ledataUpgrade libicu-32bitUpgrade icuUpgrade libicu-develUpgrade libicu-x86Upgrade libicu-devel-32bitUpgrade libicu-docUpgrade libicu77 | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade libicu34Upgrade libicu36 | Nov 8, 2024 | Jan 29, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub