Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8 in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
{ "vanir_signatures": [ { "signature_version": "v1", "deprecated": false, "target": { "file": "icu4c/source/test/intltest/callimts.cpp" }, "source": "https://github.com/unicode-org/icu/commit/89bae57bd0570109ca997e8b6b887f851b9c26e0", "digest": { "line_hashes": [ "265922437860161806218521412017495571064", "61370861690590036444881588296541572373", "21412699680533285001219682540977158554", "78524948477440916061374536654646355814", "66071699775431555534478414008159488241", "314051153806869992058837242297794192105", "18121896161909391091128965835462286211", "78524948477440916061374536654646355814" ], "threshold": 0.9 }, "signature_type": "Line", "id": "CVE-2017-15422-44666b9c" }, { "signature_version": "v1", "deprecated": false, "target": { "file": "icu4c/source/test/intltest/callimts.cpp", "function": "CalendarLimitTest::doLimitsTest" }, "source": "https://github.com/unicode-org/icu/commit/89bae57bd0570109ca997e8b6b887f851b9c26e0", "digest": { "length": 5436.0, "function_hash": "195989465204932975762316039963888273501" }, "signature_type": "Function", "id": "CVE-2017-15422-a0eae682" } ] }