Stack-based buffer overflow in the _canonicalize function in common/uloc.c in International Components for Unicode (ICU) before 49.1 allows remote attackers to execute arbitrary code via a crafted locale ID that is not properly handled during variant canonicalization.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Internationalcomponentsforunicode | — | Upgrade macOS to the latest versionApply OS X security update 2012-004 | Sep 27, 2012 | Jun 21, 2012 |
| Apple Osx Note | — | Upgrade macOS to the latest versionApply OS X security update 2012-004 | Aug 28, 2015 | Jun 21, 2012 |
| Centos_linux | — | Upgrade libicuUpgrade libicu-develUpgrade icuUpgrade libicu-doc | Dec 1, 2016 | Jun 21, 2012 |
| Debian | — | Upgrade icu | Jul 30, 2024 | Jun 21, 2012 |
| Gentoo Linux | — | Upgrade dev-libs/icu. | Oct 30, 2017 | Jun 21, 2012 |
| Oracle Solaris | — | Upgrade library/icu to version 0.5.11-0.175.0.11.0.1.108 on Solaris 11.0 | May 29, 2017 | Jun 21, 2012 |
| Oracle_linux | — | Upgrade libicuUpgrade libicu-develUpgrade libicu-docUpgrade icu | Oct 16, 2024 | Jun 21, 2012 |
| Suse | — | Upgrade libicu-docUpgrade libicu-develUpgrade libicu-devel-32bitUpgrade libicu-32bitUpgrade libicuUpgrade icuUpgrade libicu-x86 | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libicu44Upgrade libicu42 | Nov 8, 2024 | Jun 21, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub