Out-of-bounds read in icu - CVE-2016-6293
Published: May 30, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to the uloc_acceptLanguageFromHTTP function in common/uloc.cpp for C/C++ does not ensure that there is a '' character at the end of a certain temporary array. A remote unauthenticated attacker can supply a call with a long httpAcceptLanguage argument, trigger out-of-bounds read and cause the service to crash.
Affected software
phpmyadmin (Alpine package)
openSUSE Leap
icu
Fedora
How to mitigate CVE-2016-6293
icu - addressed in versions 56.1-5.fc24, 57.1-2.fc25