CVE-2014-8146
The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 does not properly track directionally isolated pieces of text, which allows…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 24.3%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 does not properly track directionally isolated pieces of text, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via crafted text.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 24.31% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- apple/itunes · apple/iphone os · apple/mac os x · apple/watchos · icu-project/international components for unicode
- Source
- secalert@redhat.com
References
- http://bugs.icu-project.org/trac/changeset/37162Issue Tracking, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.htmlMailing List
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.htmlMailing List
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00005.htmlMailing List
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlMailing List
- http://openwall.com/lists/oss-security/2015/05/05/6Mailing List
- http://seclists.org/fulldisclosure/2015/May/14Exploit, Mailing List, Third Party Advisory
- http://www.debian.org/security/2015/dsa-3323Third Party Advisory
- http://www.kb.cert.org/vuls/id/602540Third Party Advisory, US Government Resource
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlPatch
- http://www.securityfocus.com/bid/74457Third Party Advisory, VDB Entry
- https://raw.githubusercontent.com/pedrib/PoC/master/generic/i-c-u-fail.txtExploit
- https://security.gentoo.org/glsa/201507-04Third Party Advisory
- https://support.apple.com/HT205212Third Party Advisory
- https://support.apple.com/HT205213Third Party Advisory
- https://support.apple.com/HT205221Third Party Advisory
- https://support.apple.com/HT205267Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- http://bugs.icu-project.org/trac/changeset/37162Issue Tracking, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.htmlMailing List
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.htmlMailing List
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00005.htmlMailing List
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlMailing List
- http://openwall.com/lists/oss-security/2015/05/05/6Mailing List
- http://seclists.org/fulldisclosure/2015/May/14Exploit, Mailing List, Third Party Advisory
- http://www.debian.org/security/2015/dsa-3323Third Party Advisory
- http://www.kb.cert.org/vuls/id/602540Third Party Advisory, US Government Resource
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.