Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

SUSE: 2018:1401-1 Moderate: ICU Denial Of Service & Code Execution

suse
Calendar Grey May 24, 2018
Scroller Suse
Tackling security risks in ICU via SUSE's recent upgrade. Comprehensive installation and patching instructions provided.
An update that fixes 8 vulnerabilities is now available

Summary

icu was updated to fix two security issues. These security issues were fixed: - CVE-2014-8147: The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) used an integer data type that is inconsistent with a header file, which allowed remote attackers to cause a denial of service (incorrect malloc followed by invalid free) or possibly execute arbitrary code via crafted text (bsc#929629). - CVE-2014-8146: The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) did not properly track directionally isolated pieces of text, which allowed remote attackers to

References

#1034674 #1034678 #1067203 #1072193 #1077999

#1087932 #929629 #990636

Cross- CVE-2014-8146 CVE-2014-8147 CVE-2016-6293

CVE-2017-14952 CVE-2017-15422 CVE-2017-17484

CVE-2017-7867 CVE-2017-7868

Affected Products:

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Workstation Extension 12-SP3

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Server 12-SP2-LTSS

SUSE Linux Enterprise Server 12-SP1-LTSS

SUSE Linux Enterprise Server 12-LTSS

SUSE Linux Enterprise Desktop 12-SP3

SUSE Enterprise Storage 4

SUSE CaaS Platform ALL

OpenStack Clou...

Read the Full Advisory

Announcement ID: SUSE-SU-2018:1401-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.