MGASA-2017-0411

Source
https://advisories.mageia.org/MGASA-2017-0411.html
Import Source
https://advisories.mageia.org/MGASA-2017-0411.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2017-0411
Related
Published
2017-11-16T08:36:22Z
Modified
2017-11-16T08:13:49Z
Summary
Updated icu packages fix security vulnerability
Details

Updated icu packages fix security vulnerability:

Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary code via a crafted string, aka a "redundant UVector entry clean up function call" issue (CVE-2017-14952).

References
Credits

Affected packages

Mageia:6 / icu

Package

Name
icu
Purl
pkg:rpm/mageia/icu?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
58.2-3.1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / icu

Package

Name
icu
Purl
pkg:rpm/mageia/icu?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
53.1-12.8.mga5

Ecosystem specific

{
    "section": "core"
}