Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-7415

Опубликовано: 17 сент. 2016
Источник: debian
EPSS Низкий

Описание

Stack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long locale string.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
icufixed58.1-1experimentalpackage
icufixed57.1-5package

Примечания

  • Related code in http://source.icu-project.org/repos/icu/icu/trunk/source/common/locid.cpp file

  • PHP Bug: https://bugs.php.net/bug.php?id=73007

  • PHP fix: https://github.com/php/php-src/commit/6d55ba265637d6adf0ba7e9c9ef11187d1ec2f5b?w=1

  • Upstream bug: http://bugs.icu-project.org/trac/ticket/12745

EPSS

Процентиль: 84%
0.02161
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 9 лет назад

Stack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long locale string.

CVSS3: 6.5
redhat
больше 9 лет назад

Stack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long locale string.

CVSS3: 9.8
nvd
больше 9 лет назад

Stack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long locale string.

CVSS3: 9.8
github
больше 3 лет назад

Stack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long locale string.

EPSS

Процентиль: 84%
0.02161
Низкий