Date: Fri, 26 Jun 2009 13:41:51 -0500 Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Moderate: icu on SL5.x i386/x86_64 Comments: To: "scientific-linux-errata@fnal.gov" Synopsis: Moderate: icu security update Issue date: 2009-06-25 CVE Names: CVE-2009-0153 A flaw was found in the way ICU processed certain, invalid byte sequences during Unicode conversion. If an application used ICU to decode malformed, multibyte character data, it may have been possible to bypass certain content protection mechanisms, or display information in a manner misleading to the user. (CVE-2009-0153) SL 5.x SRPMS: icu-3.6-5.11.4.src.rpm i386: icu-3.6-5.11.4.i386.rpm libicu-3.6-5.11.4.i386.rpm libicu-devel-3.6-5.11.4.i386.rpm libicu-doc-3.6-5.11.4.i386.rpm x86_64: icu-3.6-5.11.4.x86_64.rpm libicu-3.6-5.11.4.i386.rpm libicu-3.6-5.11.4.x86_64.rpm libicu-devel-3.6-5.11.4.i386.rpm libicu-devel-3.6-5.11.4.x86_64.rpm libicu-doc-3.6-5.11.4.x86_64.rpm -Connie Sieh -Troy Dawson