Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary code via a crafted string, aka a "redundant UVector entry clean up function call" issue.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Oct 16, 2017 |
| Debian | — | Upgrade icu | Jul 30, 2024 | Oct 16, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade libicuUpgrade libicu-devel | Dec 4, 2017 | Oct 16, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libicu-develUpgrade libicu | Dec 4, 2017 | Oct 16, 2017 |
| Oracle Solaris | — | Upgrade library/icu to version 0.5.11-0.175.3.27.0.2.12 on Solaris 11.3Upgrade developer/icu to version 0.5.11-0.175.3.27.0.2.12 on Solaris 11.3 | Dec 19, 2017 | Oct 16, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 9, 2017 |
| Suse | — | Upgrade libicu52_1-32bitUpgrade libicu-32bitUpgrade icuUpgrade libicuUpgrade libicu-x86Upgrade libicu52_1Upgrade libicu-docUpgrade libicu52_1-dataUpgrade libicu-develUpgrade libicu-devel-32bit | May 24, 2018 | Oct 16, 2017 |
| Ubuntu | — | Upgrade libicu48Upgrade libicu52Upgrade libicu57Upgrade lib32icu48Upgrade libicu55 | Oct 23, 2017 | Oct 16, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 16, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub