Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8 in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"265922437860161806218521412017495571064",
"61370861690590036444881588296541572373",
"21412699680533285001219682540977158554",
"78524948477440916061374536654646355814",
"66071699775431555534478414008159488241",
"314051153806869992058837242297794192105",
"18121896161909391091128965835462286211",
"78524948477440916061374536654646355814"
]
},
"id": "CVE-2017-15422-44666b9c",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/unicode-org/icu/commit/89bae57bd0570109ca997e8b6b887f851b9c26e0",
"target": {
"file": "icu4c/source/test/intltest/callimts.cpp"
},
"deprecated": false
},
{
"digest": {
"function_hash": "195989465204932975762316039963888273501",
"length": 5436.0
},
"id": "CVE-2017-15422-a0eae682",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/unicode-org/icu/commit/89bae57bd0570109ca997e8b6b887f851b9c26e0",
"target": {
"file": "icu4c/source/test/intltest/callimts.cpp",
"function": "CalendarLimitTest::doLimitsTest"
},
"deprecated": false
}
]