USN-2740-1: ICU vulnerabilities
Atte Kettunen discovered that ICU incorrectly handled certain converter names. If an application using ICU processed crafted data, a remote attacker could possibly cause it to crash. (CVE-2015-1270) It was discovered that ICU incorrectly handled certain memory operations when processing data. If an application using ICU processed crafted data, a remote attacker could possibly cause it to crash or potentially execute arbitrary code with the privileges of the user invoking the program. (CVE-2015-2632, CVE-2015-4760)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-2740-1?
The severity of USN-2740-1 is moderate.
How can an attacker exploit CVE-2015-1270?
An attacker can exploit CVE-2015-1270 by sending crafted data to an application using ICU.
What is the remedy for libicu52 version 52.1-8ubuntu0.2?
The remedy for libicu52 version 52.1-8ubuntu0.2 is to update to a later version.
What is the remedy for libicu52 version 52.1-3ubuntu0.4?
The remedy for libicu52 version 52.1-3ubuntu0.4 is to update to a later version.
What is the remedy for libicu48 version 4.8.1.1-3ubuntu0.6?
The remedy for libicu48 version 4.8.1.1-3ubuntu0.6 is to update to a later version.