Back to search
CVE-2014-9654
Published: Apr 24, 2017
Modified: Aug 6, 2024
PUBLISHED
Description
The Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-12-03, as used in Google Chrome before 40.0.2214.91, calculates certain values without ensuring that they can be represented in a 24-bit field, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted string, a related issue to CVE-2014-7923.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://bugs.icu-project.org/trac/ticket/11371
x_refsource_CONFIRM
https://code.google.com/p/chromium/issues/detail?id=432209
x_refsource_CONFIRM
1035410
vdb-entry
x_refsource_SECTRACK
GLSA-201503-06
vendor-advisory
x_refsource_GENTOO
http://bugs.icu-project.org/trac/changeset/36801
x_refsource_CONFIRM
[oss-security] 20150205 Re: CVE request - ICU
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now