Back to search
CVE-2017-17484
Published: Dec 10, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
The ucnv_UTF8FromUTF8 function in ucnv_u8.cpp in International Components for Unicode (ICU) for C/C++ through 60.1 mishandles ucnv_convertEx calls for UTF-8 to UTF-8 conversion, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted string, as demonstrated by ZNC.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://ssl.icu-project.org/trac/ticket/13490
x_refsource_MISC
https://ssl.icu-project.org/trac/changeset/40714
x_refsource_MISC
https://github.com/znc/znc/issues/1459
x_refsource_MISC
https://ssl.icu-project.org/trac/attachment/ticket/13490/poc.cpp
x_refsource_MISC
https://ssl.icu-project.org/trac/ticket/13510
x_refsource_MISC
https://ssl.icu-project.org/trac/changeset/40715
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now