Stack-based buffer overflow in the uresgetByKeyWithFallback function in common/uresbund.cpp in International Components for Unicode (ICU) before 54.1 for C/C++ allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted ulocgetDisplayName call.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "icu-devtools", "binary_version": "52.1-3ubuntu0.5" }, { "binary_name": "icu-devtools-dbgsym", "binary_version": "52.1-3ubuntu0.5" }, { "binary_name": "icu-doc", "binary_version": "52.1-3ubuntu0.5" }, { "binary_name": "libicu-dev", "binary_version": "52.1-3ubuntu0.5" }, { "binary_name": "libicu-dev-dbgsym", "binary_version": "52.1-3ubuntu0.5" }, { "binary_name": "libicu52", "binary_version": "52.1-3ubuntu0.5" }, { "binary_name": "libicu52-dbg", "binary_version": "52.1-3ubuntu0.5" }, { "binary_name": "libicu52-dbgsym", "binary_version": "52.1-3ubuntu0.5" } ] }