The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that there is a '\0' character at the end of a certain temporary array, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a call with a long httpAcceptLanguage argument.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade icu | Aug 30, 2017 | Jul 25, 2016 |
| Debian | — | Upgrade icu | Nov 27, 2016 | Jul 25, 2016 |
| Gentoo Linux | — | Upgrade dev-libs/icu. | Oct 30, 2017 | Jul 25, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade php-xmlUpgrade php-soapUpgrade php-commonUpgrade php-xmlrpcUpgrade php-gdUpgrade php-processUpgrade php-mysqlUpgrade php-recodeUpgrade php-pdoUpgrade php-odbcUpgrade php-cliUpgrade phpUpgrade php-pgsqlUpgrade php-ldap | Dec 4, 2019 | Jul 25, 2016 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libicuUpgrade libicu-devel | Dec 18, 2019 | Jul 25, 2016 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libicu-develUpgrade libicu | Sep 24, 2019 | Jul 25, 2016 |
| Oracle Solaris | — | Upgrade web/php-56/extension/php-xdebug to version 2.3.2-0.175.3.22.0.2.0 on Solaris 11.3Upgrade web/php-56/extension/php-suhosin-extension to version 0.9.37.1-0.175.3.22.0.2.0 on Solaris 11.3Upgrade library/icu to version 0.5.11-0.175.3.14.0.4.4 on Solaris 11.3Upgrade developer/icu to version 0.5.11-0.175.3.14.0.4.4 on Solaris 11.3Upgrade web/php-56 to version 5.6.30-0.175.3.22.0.2.0 on Solaris 11.3 | May 29, 2017 | Jul 25, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 3, 2016 |
| Suse | — | Upgrade libicu52_1-dataUpgrade libicu-32bitUpgrade libicu52_1Upgrade libicuUpgrade icuUpgrade libicu-docUpgrade libicu-x86Upgrade libicu-devel-32bit | May 24, 2018 | Jul 25, 2016 |
| Ubuntu | — | Upgrade libicu55Upgrade libicu57Upgrade libicu48Upgrade libicu52 | Mar 14, 2017 | Jul 25, 2016 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 25, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub