Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-1270

Опубликовано: 23 июл. 2015
Источник: debian
EPSS Низкий

Описание

The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Google Chrome before 44.0.2403.89, mishandles converter names with initial x- substrings, which allows remote attackers to cause a denial of service (read of uninitialized memory) or possibly have unspecified other impact via a crafted file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
chromium-browserfixed44.0.2403.89-1package
chromium-browserend-of-lifewheezypackage
chromium-browserend-of-lifesqueezepackage
icufixed55.1-5package
icunot-affectedwheezypackage
icunot-affectedsqueezepackage

Примечания

  • http://bugs.icu-project.org/trac/ticket/11696

  • Patch: http://bugs.icu-project.org/trac/changeset/37486/

EPSS

Процентиль: 78%
0.01188
Низкий

Связанные уязвимости

ubuntu
больше 10 лет назад

The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Google Chrome before 44.0.2403.89, mishandles converter names with initial x- substrings, which allows remote attackers to cause a denial of service (read of uninitialized memory) or possibly have unspecified other impact via a crafted file.

redhat
больше 10 лет назад

The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Google Chrome before 44.0.2403.89, mishandles converter names with initial x- substrings, which allows remote attackers to cause a denial of service (read of uninitialized memory) or possibly have unspecified other impact via a crafted file.

nvd
больше 10 лет назад

The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Google Chrome before 44.0.2403.89, mishandles converter names with initial x- substrings, which allows remote attackers to cause a denial of service (read of uninitialized memory) or possibly have unspecified other impact via a crafted file.

github
больше 3 лет назад

The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Google Chrome before 44.0.2403.89, mishandles converter names with initial x- substrings, which allows remote attackers to cause a denial of service (read of uninitialized memory) or possibly have unspecified other impact via a crafted file.

fstec
больше 10 лет назад

Уязвимость браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 78%
0.01188
Низкий