CVE-2020-21913

Source
https://cve.org/CVERecord?id=CVE-2020-21913
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-21913.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-21913
Downstream
Related
Published
2021-09-20T14:15:08.160Z
Modified
2026-04-11T12:33:19.763102Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

International Components for Unicode (ICU-20850) v66.1 was discovered to contain a use after free bug in the pkg_createWithAssemblyCode function in the file tools/pkgdata/pkgdata.cpp.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "CPE_FIELD",
            "extracted_events": [
                {
                    "last_affected": "10.0"
                }
            ],
            "cpe": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*"
        },
        {
            "source": "CPE_FIELD",
            "extracted_events": [
                {
                    "last_affected": "9.0"
                }
            ],
            "cpe": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
        }
    ]
}
References

Affected packages

Git / github.com/unicode-org/icu

Affected ranges

Type
GIT
Repo
https://github.com/unicode-org/icu
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "CPE_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "66.1"
        }
    ],
    "cpe": "cpe:2.3:a:unicode:international_components_for_unicode:*:*:*:*:*:*:*:*"
}

Affected versions

Other
cldr-32-beta2
last-cvs-commit
last-svn-commit
milestone-59-0-1
milestone-60-0-1
release-59-rc
release-60-rc
release-61-rc
release-62-rc
release-63-rc
release-64-rc
release-65-rc
release-66-preview
release-66-rc

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-21913.json"