5
CVSSv2

CVE-2017-7867

Published: 14/04/2017 Updated: 23/04/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

International Components for Unicode (ICU) for C/C++ prior to 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_setNativeIndex* function.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

icu-project international components for unicode

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #860314 icu: CVE-2017-7867 CVE-2017-7868: Heap-buffer-overflow in utf8TextAccess Package: src:icu; Maintainer for src:icu is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 14 Apr 2017 12:45:01 UTC Severity: grave Tags: patch, securi ...
Several security issues were fixed in ICU ...
Several security issues were fixed in ICU ...
It was discovered that icu, the International Components for Unicode library, did not correctly validate its input An attacker could use this problem to trigger an out-of-bound write through a heap-based buffer overflow, thus causing a denial of service via application crash, or potential execution of arbitrary code For the stable distribution (j ...
A vulnerability was found in the International Components for Unicode (ICU) Specially crafted invalid utf-8 text, when parsed or manipulated using particular functions in libicu, could cause out-of-bounds heap reads and writes potentially leading to a crash, memory disclosure, or possibly code execution ...