Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-8147

Опубликовано: 25 мая 2015
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 7.5

Описание

The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 uses an integer data type that is inconsistent with a header file, which allows remote attackers to cause a denial of service (incorrect malloc followed by invalid free) or possibly execute arbitrary code via crafted text.

РелизСтатусПримечание
devel

released

52.1-8ubuntu1
esm-infra-legacy/trusty

released

52.1-3ubuntu0.3
precise

not-affected

code not present
trusty

released

52.1-3ubuntu0.3
trusty/esm

released

52.1-3ubuntu0.3
upstream

released

55.1
utopic

released

52.1-6ubuntu0.3
vivid

released

52.1-8ubuntu0.1

Показывать по

EPSS

Процентиль: 97%
0.41904
Средний

7.5 High

CVSS2

Связанные уязвимости

redhat
почти 11 лет назад

The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 uses an integer data type that is inconsistent with a header file, which allows remote attackers to cause a denial of service (incorrect malloc followed by invalid free) or possibly execute arbitrary code via crafted text.

nvd
больше 10 лет назад

The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 uses an integer data type that is inconsistent with a header file, which allows remote attackers to cause a denial of service (incorrect malloc followed by invalid free) or possibly execute arbitrary code via crafted text.

debian
больше 10 лет назад

The resolveImplicitLevels function in common/ubidi.c in the Unicode Bi ...

github
больше 3 лет назад

The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 uses an integer data type that is inconsistent with a header file, which allows remote attackers to cause a denial of service (incorrect malloc followed by invalid free) or possibly execute arbitrary code via crafted text.

fstec
больше 10 лет назад

Уязвимость библиотеки International Components for Unicode, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код

EPSS

Процентиль: 97%
0.41904
Средний

7.5 High

CVSS2