First published: Tue Oct 11 2016(Updated: )
A locale string of more than 255 characters passed to uloc_getDisplayName() could overflow a buffer on the stack, leading a crash or, potentially, code execution. Upstream patch: <a href="http://bugs.icu-project.org/trac/changeset/35699">http://bugs.icu-project.org/trac/changeset/35699</a> Upstream issue (private as at 2016-10-11): <a href="http://bugs.icu-project.org/trac/ticket/10891">http://bugs.icu-project.org/trac/ticket/10891</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/icu | <54.1 | 54.1 |
Icu-project International Components For Unicode | <54.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.