Back to search
CVE-2014-9911
Published: Jan 4, 2017
Modified: Aug 6, 2024
PUBLISHED
Description
Stack-based buffer overflow in the ures_getByKeyWithFallback function in common/uresbund.cpp in International Components for Unicode (ICU) before 54.1 for C/C++ allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted uloc_getDisplayName call.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://bugs.icu-project.org/trac/changeset/35699
x_refsource_CONFIRM
https://bugzilla.redhat.com/show_bug.cgi?id=1383569
x_refsource_CONFIRM
1037556
vdb-entry
x_refsource_SECTRACK
94520
vdb-entry
x_refsource_BID
[oss-security] 20161124 Re: CVE request: icu: stack-based buffer overflow in uloc_getDisplayName
mailing-list
x_refsource_MLIST
https://bugs.php.net/bug.php?id=67397
x_refsource_CONFIRM
http://bugs.icu-project.org/trac/ticket/1089
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now