Описание
Security update for icu
This update for icu fixes the following issues:
- CVE-2016-6293: The uloc_acceptLanguageFromHTTP function in common/uloc.cpp did not ensure that there is a '\0' character at the end of a certain temporary array, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a call with a long httpAcceptLanguage argument. (bsc#990636)
- CVE-2017-7868: ICU had an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_moveIndex32* function. (bsc#1034674)
- CVE-2017-7867: ICU had an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_setNativeIndex* function. (bsc#1034678)
- CVE-2017-14952: Double free in i18n/zonemeta.cpp allowed remote attackers to execute arbitrary code via a crafted string, aka a 'redundant UVector entry clean up function call' issue. (bsc#1067203)
- CVE-2017-17484:The ucnv_UTF8FromUTF8 function in ucnv_u8.cpp mishandled ucnv_convertEx calls for UTF-8 to UTF-8 conversion, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted string, as demonstrated by ZNC. (bsc#1072193)
- CVE-2017-15422: An integer overflow in persian calendar calculation was fixed, which could show wrong years. (bsc#1077999)
Список пакетов
SUSE Linux Enterprise Server 11 SP4
SUSE Linux Enterprise Server for SAP Applications 11 SP4
SUSE Linux Enterprise Software Development Kit 11 SP4
Ссылки
- Link for SUSE-SU-2018:1602-1
- E-Mail link for SUSE-SU-2018:1602-1
- SUSE Security Ratings
- SUSE Bug 1034674
- SUSE Bug 1034678
- SUSE Bug 1067203
- SUSE Bug 1072193
- SUSE Bug 1077999
- SUSE Bug 990636
- SUSE CVE CVE-2016-6293 page
- SUSE CVE CVE-2017-14952 page
- SUSE CVE CVE-2017-15422 page
- SUSE CVE CVE-2017-17484 page
- SUSE CVE CVE-2017-7867 page
- SUSE CVE CVE-2017-7868 page
Описание
The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that there is a '\0' character at the end of a certain temporary array, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a call with a long httpAcceptLanguage argument.
Затронутые продукты
Ссылки
- CVE-2016-6293
- SUSE Bug 1035111
- SUSE Bug 1123121
- SUSE Bug 990636
Описание
Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary code via a crafted string, aka a "redundant UVector entry clean up function call" issue.
Затронутые продукты
Ссылки
- CVE-2017-14952
- SUSE Bug 1067203
- SUSE Bug 1123121
Описание
Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8 in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2017-15422
- SUSE Bug 1071691
- SUSE Bug 1077999
- SUSE Bug 1123121
Описание
The ucnv_UTF8FromUTF8 function in ucnv_u8.cpp in International Components for Unicode (ICU) for C/C++ through 60.1 mishandles ucnv_convertEx calls for UTF-8 to UTF-8 conversion, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted string, as demonstrated by ZNC.
Затронутые продукты
Ссылки
- CVE-2017-17484
- SUSE Bug 1072193
- SUSE Bug 1123121
Описание
International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_setNativeIndex* function.
Затронутые продукты
Ссылки
- CVE-2017-7867
- SUSE Bug 1034678
- SUSE Bug 1123121
Описание
International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_moveIndex32* function.
Затронутые продукты
Ссылки
- CVE-2017-7868
- SUSE Bug 1034674
- SUSE Bug 1123121