First published: Wed Sep 16 2015(Updated: )
Atte Kettunen discovered that ICU incorrectly handled certain converter names. If an application using ICU processed crafted data, a remote attacker could possibly cause it to crash. (CVE-2015-1270) It was discovered that ICU incorrectly handled certain memory operations when processing data. If an application using ICU processed crafted data, a remote attacker could possibly cause it to crash or potentially execute arbitrary code with the privileges of the user invoking the program. (CVE-2015-2632, CVE-2015-4760)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libicu52 | <52.1-8ubuntu0.2 | 52.1-8ubuntu0.2 |
=15.04 | ||
All of | ||
ubuntu/libicu52 | <52.1-3ubuntu0.4 | 52.1-3ubuntu0.4 |
=14.04 | ||
All of | ||
ubuntu/libicu48 | <4.8.1.1-3ubuntu0.6 | 4.8.1.1-3ubuntu0.6 |
=12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of USN-2740-1 is moderate.
An attacker can exploit CVE-2015-1270 by sending crafted data to an application using ICU.
The remedy for libicu52 version 52.1-8ubuntu0.2 is to update to a later version.
The remedy for libicu52 version 52.1-3ubuntu0.4 is to update to a later version.
The remedy for libicu48 version 4.8.1.1-3ubuntu0.6 is to update to a later version.