-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-6084 2015-04-13 03:19:38 -------------------------------------------------------------------------------- Name : icu Product : Fedora 20 Version : 50.1.2 Release : 12.fc20 URL : https://www.icu-project.org/ Summary : International Components for Unicode Description : Tools and utilities for developing with icu. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2014-9654, CVE-2014-7923, CVE-2014-7926 -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 10 2015 Eike Rathke- 50.1.2-12 - Resolves: rhbz#1184811 CVE-2014-6585 CVE-2014-6591 * Mon Mar 9 2015 Eike Rathke - 50.1.2-11 - TestTwoDigitYear build fix - Resolves: rhbz#1184811 CVE-2014-6585 CVE-2014-6591 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1185202 - CVE-2014-7923 ICU: regexp engine missing look-behind expression range check https://bugzilla.redhat.com/show_bug.cgi?id=1185202 [ 2 ] Bug #1185205 - CVE-2014-7926 ICU: regexp engine incorrect handling of a zero length quantifier https://bugzilla.redhat.com/show_bug.cgi?id=1185205 [ 3 ] Bug #1190129 - CVE-2014-9654 icu: insufficient size limit checks in regular expression compiler https://bugzilla.redhat.com/show_bug.cgi?id=1190129 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update icu' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-announce