ALAS2-2023-2172

Related Vulnerabilities: CVE-2020-21913  

International Components for Unicode (ICU-20850) v66.1 was discovered to contain a use after free bug in the pkg_createWithAssemblyCode function in the file tools/pkgdata/pkgdata.cpp. (CVE-2020-21913)

ALAS2-2023-2172


Amazon Linux 2 Security Advisory: ALAS-2023-2172
Advisory Release Date: 2023-07-20 17:30 Pacific
Advisory Updated Date: 2023-07-25 23:06 Pacific
Severity: Medium

Issue Overview:

International Components for Unicode (ICU-20850) v66.1 was discovered to contain a use after free bug in the pkg_createWithAssemblyCode function in the file tools/pkgdata/pkgdata.cpp. (CVE-2020-21913)


Affected Packages:

libicu60


Issue Correction:
Run yum update libicu60 to update your system.

New Packages:
aarch64:
    libicu60-60.3-2.amzn2.0.2.aarch64
    libicu60-devel-60.3-2.amzn2.0.2.aarch64
    libicu60-debuginfo-60.3-2.amzn2.0.2.aarch64

i686:
    libicu60-60.3-2.amzn2.0.2.i686
    libicu60-devel-60.3-2.amzn2.0.2.i686
    libicu60-debuginfo-60.3-2.amzn2.0.2.i686

noarch:
    libicu60-doc-60.3-2.amzn2.0.2.noarch

src:
    libicu60-60.3-2.amzn2.0.2.src

x86_64:
    libicu60-60.3-2.amzn2.0.2.x86_64
    libicu60-devel-60.3-2.amzn2.0.2.x86_64
    libicu60-debuginfo-60.3-2.amzn2.0.2.x86_64