| PROBLEM: | The International Components for Unicode library (libicu) is prone to multiple memory-corruption vulnerabilities. |
| PLATFORM: | libicu 3.8.1 and prior versions Debian GNU/Linux 4.0 (etch) |
| DAMAGE: | Allows remote attackers to corrupt and overflow memory and possibly execute remote code. |
| SOLUTION: | Upgrade to the appropriate version. |
| VULNERABILITY ASSESSMENT: |
The risk is MEDIUM. Successfully exploiting these issues allows remote attackers to corrupt and overflow memory and possibly execute remote code. Failed exploit attempts will likely crash applications. |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/s-136.shtml |
| ORIGINAL BULLETIN: | http://www.securityfocus.com/bid/27455/discuss |
| ADDITIONAL LINK: | http://www.debian.org/security/2008/dsa-1511 |
| CVE: | CVE-2007-4770 CVE-2007-4771 |
REVISION HISTORY:
03/04/2008 - revised S-136 to add a link to Debian Security Advisory DSA-1511-1 for
Debian GNU/Linux 4.0 (etch).
[***** Start Security Focus 27455 *****]
Bugtraq ID: 27455
Class: Unknown
CVE: CVE-2007-4770
CVE-2007-4771
Remote: Yes
Local: No
Published: Jan 25 2008 12:00AM
Updated: Jan 28 2008 07:27PM
Credit: Will Drewry is credited with the discovery of these issues.
Vulnerable: RedHat Fedora 8 0
RedHat Fedora 7 0
RedHat Enterprise Linux Desktop Workstation 5 client
RedHat Enterprise Linux Desktop 5 client
RedHat Enterprise Linux 5 server
MandrakeSoft Linux Mandrake 2008.0 x86_64
MandrakeSoft Linux Mandrake 2008.0
ICU Project International Components for Unicode 3.8.1
ICU Project International Components for Unicode 3.8
ICU Project International Components for Unicode 3.6
ICU Project International Components for Unicode 0
[***** End Security Focus 27455 *****]
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org