Jump to content
Compatible Support Forums
Sign in to follow this  
news

[SECURITY] [DLA 283-1] icu security update

Recommended Posts

Package : icu

Version : 4.4.1-8+squeeze4

CVE ID : CVE-2015-4760

 

A vulnerability has been found in the International Components

for Unicode (ICU) library:

 

CVE-2015-4760

 

It was discovered that ICU Layout Engine was missing multiple

boundary checks. These could lead to buffer overflows and memory

corruption. A specially crafted file could cause an application

using ICU to parse untrusted font files to crash and, possibly,

execute arbitrary code.

 

For the squeeze distribution, these issues have been fixed in version

4.4.1-8+squeeze4 of icu.

 

We recommend to upgrade your icu packages.

 

 

Share this post


Link to post

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
Sign in to follow this  

×