Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Ubuntu 12.04 ESM: USN-3458-2 Critical: ICU Arbitrary Code Execution

ubuntu
Calendar Grey October 23, 2017
Scroller Ubuntu
Discover Ubuntu USN-3458-2 addressing ICU vulnerability leading to security risks from crafted input.
ICU could be made to crash or run arbitrary code as your login if it received specially crafted input.

Summary

ICU could be made to crash or run arbitrary code as your login

if it received specially crafted input.

Software Description:

- icu: International Components for Unicode library

Details:

USN-3458-1 fixed a vulnerability in ICU. This update

provides the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

 It was discovered that ICU incorrectly handled certain inputs. If an

 application using ICU processed crafted data, a remote attacker could

 possibly cause it to crash or potentially execute arbitrary code with

 the privileges of the user invoking the program.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  lib32icu48                      4.8.1.1-3ubuntu0.9
  libicu48                        4.8.1.1-3ubuntu0.9

In general, a standard system update will make all the necessary
changes.

References

  https://ubuntu.com/security/notices/USN-3458-2

  https://ubuntu.com/security/notices/USN-3458-1

  CVE-2017-14952

Severity
critical
Lowest
Low
Medium
High
Critical

October 23, 2017

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.