A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.
{
"priority_reason": "DoS in a command line tool only",
"binaries": [
{
"binary_name": "icu-devtools",
"binary_version": "60.2-3ubuntu3.2"
},
{
"binary_name": "libicu-dev",
"binary_version": "60.2-3ubuntu3.2"
},
{
"binary_name": "libicu60",
"binary_version": "60.2-3ubuntu3.2"
},
{
"binary_name": "libiculx60",
"binary_version": "60.2-3ubuntu3.2"
}
]
}{
"priority_reason": "DoS in a command line tool only",
"binaries": [
{
"binary_name": "icu-devtools",
"binary_version": "66.1-2ubuntu2.1"
},
{
"binary_name": "libicu-dev",
"binary_version": "66.1-2ubuntu2.1"
},
{
"binary_name": "libicu66",
"binary_version": "66.1-2ubuntu2.1"
}
]
}{
"priority_reason": "DoS in a command line tool only",
"binaries": [
{
"binary_name": "icu-devtools",
"binary_version": "74.2-1ubuntu3.1"
},
{
"binary_name": "libicu-dev",
"binary_version": "74.2-1ubuntu3.1"
},
{
"binary_name": "libicu74",
"binary_version": "74.2-1ubuntu3.1"
}
]
}{
"priority_reason": "DoS in a command line tool only",
"binaries": [
{
"binary_name": "icu-devtools",
"binary_version": "52.1-3ubuntu0.8+esm2"
},
{
"binary_name": "libicu-dev",
"binary_version": "52.1-3ubuntu0.8+esm2"
},
{
"binary_name": "libicu52",
"binary_version": "52.1-3ubuntu0.8+esm2"
}
]
}{
"priority_reason": "DoS in a command line tool only",
"binaries": [
{
"binary_name": "icu-devtools",
"binary_version": "55.1-7ubuntu0.5+esm1"
},
{
"binary_name": "libicu-dev",
"binary_version": "55.1-7ubuntu0.5+esm1"
},
{
"binary_name": "libicu55",
"binary_version": "55.1-7ubuntu0.5+esm1"
}
]
}