The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Google Chrome before 44.0.2403.89, mishandles converter names with initial x- substrings, which allows remote attackers to cause a denial of service (read of uninitialized memory) or possibly have unspecified other impact via a crafted file.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade icu | Aug 30, 2017 | Jul 22, 2015 |
| Debian | — | Upgrade icu | Jul 30, 2024 | Jul 23, 2015 |
| Freebsd | — | Upgrade chromiumUpgrade chromium-pulseUpgrade chromium-npapi | Dec 10, 2025 | Jul 25, 2015 |
| Gentoo Linux | — | Upgrade www-client/chromium. | Oct 30, 2017 | Jul 22, 2015 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Jul 27, 2015 | Jul 21, 2015 |
| Oracle Solaris | — | Upgrade developer/icu to version 0.5.11-0.175.3.2.0.3.1 on Solaris 11.3Upgrade library/icu to version 0.5.11-0.175.3.2.0.3.1 on Solaris 11.3 | May 29, 2017 | Jul 22, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 21, 2015 |
| Suse | — | Upgrade chromium | Dec 18, 2015 | Jul 22, 2015 |
| Ubuntu | — | Upgrade libicu48Upgrade libicu52Upgrade liboxideqtcore0 | Nov 8, 2024 | Jul 23, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub