Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-6293

Опубликовано: 03 июл. 2016
Источник: redhat
CVSS3: 3.3
CVSS2: 4.3
EPSS Низкий

Описание

The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that there is a '\0' character at the end of a certain temporary array, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a call with a long httpAcceptLanguage argument.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 8icuWill not fix
Red Hat Enterprise Linux 5icuWill not fix
Red Hat Enterprise Linux 6icuWill not fix
Red Hat Enterprise Linux 7icuWill not fix
Red Hat OpenShift Enterprise 2icuWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1360339icu: Out-of-bounds access in uloc_acceptLanguageFromHTTP

EPSS

Процентиль: 87%
0.03557
Низкий

3.3 Low

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 9 лет назад

The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that there is a '\0' character at the end of a certain temporary array, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a call with a long httpAcceptLanguage argument.

CVSS3: 9.8
nvd
больше 9 лет назад

The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that there is a '\0' character at the end of a certain temporary array, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a call with a long httpAcceptLanguage argument.

CVSS3: 9.8
debian
больше 9 лет назад

The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in Interna ...

CVSS3: 9.8
github
больше 3 лет назад

The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that there is a '\0' character at the end of a certain temporary array, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a call with a long httpAcceptLanguage argument.

suse-cvrf
больше 7 лет назад

Security update for icu

EPSS

Процентиль: 87%
0.03557
Низкий

3.3 Low

CVSS3

4.3 Medium

CVSS2