USN-2740-1
Dashboard / Vulnerabilities / USN-2740-1
USN-2740-1
Summary: icu vulnerabilities
Details: Atte Kettunen discovered that ICU incorrectly handled certain converter names. If an application using ICU processed crafted data, a remote attacker could possibly cause it to crash. (CVE-2015-1270) It was discovered that ICU incorrectly handled certain memory operations when processing data. If an application using ICU processed crafted data, a remote attacker could possibly cause it to crash or potentially execute arbitrary code with the privileges of the user invoking the program. (CVE-2015-2632, CVE-2015-4760)
References: https://ubuntu.com/security/notices/USN-2740-1, https://ubuntu.com/security/CVE-2015-1270, https://ubuntu.com/security/CVE-2015-2632, https://ubuntu.com/security/CVE-2015-4760
Affected packages
Package
Name: icu
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
