Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2017-15422

Published: 7 December 2017

Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8 in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

Notes

AuthorNote
leosilva
same as wheezy, precise/esm is not affected code is not present.

Priority

Medium

CVSS 3 base score: 6.5

Status

Package Release Status
chromium-browser
Launchpad, Ubuntu, Debian
artful
Released (63.0.3239.84-0ubuntu0.17.10.1)
bionic
Released (63.0.3239.84-0ubuntu1)
cosmic
Released (63.0.3239.84-0ubuntu1)
precise Does not exist

trusty Does not exist
(trusty was released [63.0.3239.84-0ubuntu0.14.04.1])
upstream
Released (63.0.3239.84)
xenial
Released (63.0.3239.84-0ubuntu0.16.04.1)
zesty
Released (63.0.3239.84-0ubuntu0.17.04.1)
icu
Launchpad, Ubuntu, Debian
artful
Released (57.1-6ubuntu0.3)
bionic Not vulnerable
(60.2-3ubuntu3)
cosmic Not vulnerable
(60.2-3ubuntu3)
precise Not vulnerable
(code not present)
trusty
Released (52.1-3ubuntu0.8)
upstream Needs triage

xenial
Released (55.1-7ubuntu0.4)
zesty Ignored
(reached end-of-life)
Patches:
upstream: http://bugs.icu-project.org/trac/changeset/40654
oxide-qt
Launchpad, Ubuntu, Debian
artful Ignored
(reached end-of-life)
bionic Does not exist

cosmic Does not exist

precise Does not exist

trusty Does not exist
(trusty was ignored [Ubuntu touch end-of-life])
upstream Needs triage

xenial Ignored
(Ubuntu touch end-of-life)
zesty Ignored
(reached end-of-life)