CVE-2017-14952

Description

Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary code via a crafted string, aka a redundant UVector entry clean up function call issue.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
2.941

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
Multiple Vulnerabilities are affected in IBM Planning Analytics Local 2.0Windows
International Components for Unicode library (USN-3274-1) libicu52_52.1-3ubuntu0.7_i386.debLinux
International Components for Unicode library (USN-3274-1) libicu52_52.1-3ubuntu0.7_amd64.debLinux
International Components for Unicode library (USN-3274-1) libicu55_55.1-7ubuntu0.3_i386.debLinux
International Components for Unicode library (USN-3274-1) libicu55_55.1-7ubuntu0.3_amd64.debLinux
International Components for Unicode library (USN-3274-1) libicu57_57.1-5ubuntu0.2_i386.debLinux
International Components for Unicode library (USN-3274-1) libicu57_57.1-5ubuntu0.2_amd64.debLinux
International Components for Unicode library (USN-3458-1) libicu52_52.1-3ubuntu0.7_i386.debLinux
International Components for Unicode library (USN-3458-1) libicu52_52.1-3ubuntu0.7_amd64.debLinux
International Components for Unicode library (USN-3458-1) libicu55_55.1-7ubuntu0.3_i386.debLinux
International Components for Unicode library (USN-3458-1) libicu55_55.1-7ubuntu0.3_amd64.debLinux
International Components for Unicode library (USN-3458-1) libicu57_57.1-6ubuntu0.2_i386.debLinux
International Components for Unicode library (USN-3458-1) libicu57_57.1-6ubuntu0.2_amd64.debLinux
SUSE-SU-2018:1401-1(SUSE Linux Enterprise Desktop 12-SP3 ) icu-52.1-8.7.1.x86_64.rpmLinux
SUSE-SU-2018:1401-1(SUSE Linux Enterprise Desktop 12-SP3 ) icu-debuginfo-52.1-8.7.1.x86_64.rpmLinux
SUSE-SU-2018:1401-1(SUSE Linux Enterprise Desktop 12-SP3 ) icu-debugsource-52.1-8.7.1.x86_64.rpmLinux
SUSE-SU-2018:1401-1(SUSE Linux Enterprise Server 12-SP3 ) libicu-doc-52.1-8.7.1.x86_64.rpmLinux
SUSE-SU-2018:1401-1(SUSE Linux Enterprise Desktop 12-SP3 ) libicu52_1-52.1-8.7.1.x86_64.rpmLinux
SUSE-SU-2018:1401-1(SUSE Linux Enterprise Desktop 12-SP3 ) libicu52_1-32bit-52.1-8.7.1.x86_64.rpmLinux
SUSE-SU-2018:1401-1(SUSE Linux Enterprise Desktop 12-SP3 ) libicu52_1-data-52.1-8.7.1.x86_64.rpmLinux
SUSE-SU-2018:1401-1(SUSE Linux Enterprise Desktop 12-SP3 ) libicu52_1-debuginfo-52.1-8.7.1.x86_64.rpmLinux
SUSE-SU-2018:1401-1(SUSE Linux Enterprise Desktop 12-SP3 ) libicu52_1-debuginfo-32bit-52.1-8.7.1.x86_64.rpmLinux
SUSE-SU-2018:1602-1(SUSE Linux Enterprise Server 11-SP4 ) libicu-4.0-47.6.1.x86_64.rpmLinux
SUSE-SU-2018:1602-1(SUSE Linux Enterprise Server 11-SP4 ) libicu-32bit-4.0-47.6.1.x86_64.rpmLinux
SUSE-SU-2018:1602-1(SUSE Linux Enterprise Server 11-SP4 ) libicu-doc-4.0-47.6.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234