Upstream details at : https://access.redhat.com/errata/RHSA-2020:0896. CentOS Errata and Security Advisory 2020:0896 Important Upstream details at : https://access.redhat.com/errata/RHSA-2020:0896 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) i386: 2ca2af516c855425dff52c4ca4e3d7333751162a57c42f5e5b26684c51cfd4f2 icu-4.2.1-15.el6_10.i686.rpm 061439620ea7c619e47a25c5275c18dce5b7dbe575082783df379a151bb86ac3 libicu-4.2.1-15.el6_10.i686.rpm 4101685dd95347909b98de52c54debc30c15bac854356410773eafbac1cadf02 libicu-devel-4.2.1-15.el6_10.i686.rpm 55f1fdb85073afad06542283b0f271b4b30eb89fd29731bf2123641e4ec4138c libicu-doc-4.2.1-15.el6_10.noarch.rpm x86_64: 6cd6a6c00d1fe46fe6a6ff4d1b10dc29ce4241e5eac30fcd61eb228d301ad015 icu-4.2.1-15.el6_10.x86_64.rpm 061439620ea7c619e47a25c5275c18dce5b7dbe575082783df379a151bb86ac3 libicu-4.2.1-15.el6_10.i686.rpm a64311636c7d0ed2c41ee67d3bb3aa7c87dd2b3a14e4032d304e5931fa730c9b libicu-4.2.1-15.el6_10.x86_64.rpm 4101685dd95347909b98de52c54debc30c15bac854356410773eafbac1cadf02 libicu-devel-4.2.1-15.el6_10.i686.rpm 91deb37d9d5bf067ffc12157d580b87784654fc0544a647b5ba3a97c23fec55d libicu-devel-4.2.1-15.el6_10.x86_64.rpm 55f1fdb85073afad06542283b0f271b4b30eb89fd29731bf2123641e4ec4138c libicu-doc-4.2.1-15.el6_10.noarch.rpm Source: 3e987588a27620f13c18a79ba858a3d8f5a986f1bf9e40e841750e5209050c70 icu-4.2.1-15.el6_10.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #
The package icu before version 60.1-1 is vulnerable to arbitrary code execution. . Arch Linux Security Advisory ASA-201711-25 ========================================= Severity: Critical Date : 2017-11-19 CVE-ID : CVE-2017-14952 Package : icu Type : arbitrary code execution Remote : Yes Link : https://security.archlinux.org/AVG-504 Summary ====== The package icu before version 60.1-1 is vulnerable to arbitrary code execution. Resolution ========= Upgrade to 60.1-1. # pacman -Syu "icu> =60.1-1" The problem has been fixed upstream in version 60.1. Workaround ========= None. Description ========== Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary code via a crafted string, aka a "redundant UVector entry clean up function call" issue. Impact ===== A remote attacker is able to execute arbitrary code on the affected host via a specially crafted string. References ========= https://unicode-org.atlassian.net https://www.sourcebrella.com/blog/double-free-vulnerability-international-components-unicode-icu/ https://security.archlinux.org/CVE-2017-14952 . The Arch Linux Security Advisory ASA-201711-25 warns of a critical vulnerability in the ICU package, enabling remote code execution, urging users to upgrade to secure versions. Arch Linux, ICU Package, Critical Alert, Remote Code Execution. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.