Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 635280 (CVE-2017-14952) - <dev-libs/icu-{58.2-r1,60.2}: Double-Free vulnerability in i18n/zonemeta.cpp
Summary: <dev-libs/icu-{58.2-r1,60.2}: Double-Free vulnerability in i18n/zonemeta.cpp
Status: RESOLVED OBSOLETE
Alias: CVE-2017-14952
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B2 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-10-24 10:58 UTC by Eddie Chapman
Modified: 2018-04-03 15:17 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Eddie Chapman 2017-10-24 10:58:19 UTC
From Mitre entry:
Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary code via a crafted string, aka a "redundant UVector entry clean up function call" issue.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14952
http://www.sourcebrella.com/blog/double-free-vulnerability-international-components-unicode-icu/
http://bugs.icu-project.org/trac/changeset/40324/trunk/icu4c/source/i18n/zonemeta.cpp

The upstream fix applies and builds fine, unmodified, when applied to current stable dev-libs/icu-58.2-r1 via /etc/portage/patches.
Comment 1 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-10-24 18:49:23 UTC
Thank you(In reply to Eddie Chapman from comment #0)
> 
> The upstream fix applies and builds fine, unmodified, when applied to
> current stable dev-libs/icu-58.2-r1 via /etc/portage/patches.

Thank you for reporting and testing.



@Maintainers please confirm and call for stabilization when ready.

Thank you
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2018-04-03 15:17:08 UTC
Fixed by the noted versions which are already stable in the tree.