First published: Thu Mar 12 2009(Updated: )
The International Components for Unicode (ICU) library provides robust and<br>full-featured Unicode services.<br>A flaw was found in the way ICU processed certain, invalid, encoded data.<br>If an application used ICU to decode malformed, multibyte, character data,<br>it may have been possible to bypass certain content protection mechanisms,<br>or display information in a manner misleading to the user. (CVE-2008-1036)<br>All users of icu should upgrade to these updated packages, which contain<br>backported patches to resolve these issues.
Affected Software | Affected Version | How to fix |
---|---|---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2009:0296 is classified as moderate.
To fix RHSA-2009:0296, you should update the International Components for Unicode (ICU) library to the latest version provided by your distribution.
RHSA-2009:0296 affects applications that utilize the International Components for Unicode (ICU) library for decoding character data.
RHSA-2009:0296 identifies a flaw in the processing of invalid encoded data by the ICU library.
If you are using an affected version of ICU, it is important to apply the recommended security updates to mitigate potential risks.