Heap-based buffer overflow in icu - CVE-2014-8146
Published: May 28, 2018 / Updated: June 17, 2021
Vulnerability details
The vulnerability allows a remote attacker to cause Dos condition or execute arbitrary code on the target system.
The vulnerability exists due to heap-based buffer overflow when the resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C does not properly track directionally isolated pieces of text. A remote unauthenticated attacker can supply specially crafted text file, trigger memory corruption and cause the service to crash or execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
Ubuntu
IBM DataPower Gateway
openSUSE Leap
icu (Alpine package)
Storage Defender – Data Protect
IBM Rational ClearQuest
How to mitigate CVE-2014-8146
icu (Alpine package) - update to 52.1-r1
Storage Defender – Data Protect - update to 2.0
IBM Rational ClearQuest - update to 10.0.6
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- OpenSUSE Linux update for icu
- Ubuntu update for ICU
- Gentoo update for International Components for Unicode
- Heap-based buffer overflow in icu (Alpine package)
- Multiple vulnerabilities in IBM DataPower Gateway Virtual Edition
- Multiple vulnerabilities in IBM Storage Defender - Data Protect
- Multiple vulnerabilities in IBM Rational ClearQuest