First published: Sun Nov 04 2018(Updated: )
International Components for Unicode (ICU) for C/C++ 63.1 has an integer overflow in number::impl::DecimalQuantity::toScientificString() in i18n/number_decimalquantity.cpp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Icu-project International Components For Unicode | =63.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-18928 is critical with a CVSS score of 9.8.
The affected software for CVE-2018-18928 is International Components for Unicode (ICU) for C/C++ version 63.1.
The CWE ID for CVE-2018-18928 is 190.
The integer overflow vulnerability in CVE-2018-18928 can be exploited by triggering the overflow condition in the number::impl::DecimalQuantity::toScientificString() function.
Yes, a fix has been provided in the identified commits and patches.