7.5
CVSSv2

CVE-2017-14952

Published: 16/10/2017 Updated: 23/04/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ up to and including 59.1 allows remote malicious users to execute arbitrary code via a crafted string, aka a "redundant UVector entry clean up function call" issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

icu-project international components for unicode

Vendor Advisories

Debian Bug report logs - #878840 icu: CVE-2017-14952: Double free in i18n/zonemetacpp Package: src:icu; Maintainer for src:icu is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 17 Oct 2017 04:39:01 UTC Severity: grave Tags: patch, security, upstream Found ...
ICU could be made to crash or run arbitrary code as your login if it received specially crafted input ...
ICU could be made to crash or run arbitrary code as your login if it received specially crafted input ...
Double free in i18n/zonemetacpp in International Components for Unicode (ICU) for C/C++ through 591 allows remote attackers to execute arbitrary code via a crafted string, aka a "redundant UVector entry clean up function call" issue ...
Double free in i18n/zonemetacpp in International Components for Unicode (ICU) for C/C++ through 591 allows remote attackers to execute arbitrary code via a crafted string, aka a "redundant UVector entry clean up function call" issue ...