UBUNTU-CVE-2017-14952
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-14952
UBUNTU-CVE-2017-14952
Summary:
Details: Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary code via a crafted string, aka a "redundant UVector entry clean up function call" issue.
References: https://ubuntu.com/security/CVE-2017-14952, http://bugs.icu-project.org/trac/changeset/40324/trunk/icu4c/source/i18n/zonemeta.cpp, http://www.sourcebrella.com/blog/double-free-vulnerability-international-components-unicode-icu/, https://ubuntu.com/security/notices/USN-3458-1, https://ubuntu.com/security/notices/USN-3458-2, https://www.cve.org/CVERecord?id=CVE-2017-14952
Affected packages
Package
Name: icu
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
