Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-10531

Опубликовано: 12 мар. 2020
Источник: debian
EPSS Низкий

Описание

An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
icufixed66.1-2experimentalpackage
icufixed63.2-3package

Примечания

  • https://bugs.chromium.org/p/chromium/issues/detail?id=1044570 (not public)

  • Upstream ICU bug: https://unicode-org.atlassian.net/browse/ICU-20958 (private)

  • Fixed by: https://github.com/unicode-org/icu/commit/b7d08bc04a4296982fcef8b6b8a354a9e4e7afca

  • https://github.com/unicode-org/icu/pull/971

EPSS

Процентиль: 70%
0.0064
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 5 лет назад

An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.

CVSS3: 8.8
redhat
больше 5 лет назад

An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.

CVSS3: 8.8
nvd
больше 5 лет назад

An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.

suse-cvrf
около 5 лет назад

Security update for icu

suse-cvrf
около 5 лет назад

Security update for icu

EPSS

Процентиль: 70%
0.0064
Низкий