CVE-2011-4599

Description

Stack-based buffer overflow in the _canonicalize function in common/uloc.c in International Components for Unicode (ICU) before 49.1 allows remote attackers to execute arbitrary code via a crafted locale ID that is not properly handled during variant canonicalization.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
35.758

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
Multiple Vulnerabilities are affected in IBM Planning Analytics Local 2.0Windows
Multiple vulnerabilities are fixed in OS X Lion Update 10.7.5 (Client)Mac
Multiple vulnerabilities are fixed in OS X Lion Update 10.7.5 (Client Combo)Mac
(RHSA-2011:1815) Moderate: icu security update icu-4.2.1-9.1.el6_2.i686.rpmLinux
(RHSA-2011:1815) Moderate: icu security update icu-4.2.1-9.1.el6_2.x86_64.rpmLinux
(RHSA-2011:1815) Moderate: icu security update libicu-4.2.1-9.1.el6_2.i686.rpmLinux
(RHSA-2011:1815) Moderate: icu security update libicu-4.2.1-9.1.el6_2.x86_64.rpmLinux
(RHSA-2011:1815) Moderate: icu security update libicu-devel-4.2.1-9.1.el6_2.i686.rpmLinux
(RHSA-2011:1815) Moderate: icu security update libicu-devel-4.2.1-9.1.el6_2.x86_64.rpmLinux
(RHSA-2011:1815) Moderate: icu security update libicu-doc-4.2.1-9.1.el6_2.noarch.rpmLinux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-600003OS X Lion Update 10.7.5 (Client)
PATCH-600004OS X Lion Update 10.7.5 (Client Combo)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234