ALAS2-2023-2171

Related Vulnerabilities: CVE-2020-21913  

International Components for Unicode (ICU-20850) v66.1 was discovered to contain a use after free bug in the pkg_createWithAssemblyCode function in the file tools/pkgdata/pkgdata.cpp. (CVE-2020-21913)

ALAS2-2023-2171


Amazon Linux 2 Security Advisory: ALAS-2023-2171
Advisory Release Date: 2023-07-20 17:30 Pacific
Advisory Updated Date: 2023-07-25 23:06 Pacific
Severity: Medium

Issue Overview:

International Components for Unicode (ICU-20850) v66.1 was discovered to contain a use after free bug in the pkg_createWithAssemblyCode function in the file tools/pkgdata/pkgdata.cpp. (CVE-2020-21913)


Affected Packages:

icu


Issue Correction:
Run yum update icu to update your system.

New Packages:
aarch64:
    icu-50.2-4.amzn2.0.1.aarch64
    libicu-50.2-4.amzn2.0.1.aarch64
    libicu-devel-50.2-4.amzn2.0.1.aarch64
    icu-debuginfo-50.2-4.amzn2.0.1.aarch64

i686:
    icu-50.2-4.amzn2.0.1.i686
    libicu-50.2-4.amzn2.0.1.i686
    libicu-devel-50.2-4.amzn2.0.1.i686
    icu-debuginfo-50.2-4.amzn2.0.1.i686

noarch:
    libicu-doc-50.2-4.amzn2.0.1.noarch

src:
    icu-50.2-4.amzn2.0.1.src

x86_64:
    icu-50.2-4.amzn2.0.1.x86_64
    libicu-50.2-4.amzn2.0.1.x86_64
    libicu-devel-50.2-4.amzn2.0.1.x86_64
    icu-debuginfo-50.2-4.amzn2.0.1.x86_64