Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian ICU Update DSA-3725-1 Critical Buffer Overflow Risks

debian
Calendar Grey November 27, 2016
Debian Logo
Debian DSA-4725-2 resolves several issues in OpenSSL library, bolstering protection for the impacted platforms.
Several vulnerabilities were discovered in the International Components for Unicode (ICU) library

Summary

CVE-2014-9911

Michele Spagnuolo discovered a buffer overflow vulnerability which
might allow remote attackers to cause a denial of service or possibly
execute arbitrary code via crafted text.

CVE-2015-2632

An integer overflow vulnerability might lead into a denial of service
or disclosure of portion of application memory if an attacker has
control on the input file.

CVE-2015-4844

Buffer overflow vulnerabilities might allow an attacker with control
on the font file to perform a denial of service attacker or,
possibly, execute arbitrary code.

CVE-2016-0494

Integer signedness issues were introduced as part of the
CVE-2015-4844 fix.

CVE-2016-6293

A buffer overflow might allow an attacker to perform a denial of
service or disclosure of portion of application memory.

CVE-2016-7415

A stack-based buffer overflow might allow an attacker with control on
the locale string to perform a denial of service and, possibly,
execute arbitrary code.

For the sta...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: icu
CVE ID: CVE-2014-9911 CVE-2015-2632 CVE-2015-4844 CVE-2016-0494

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here