Double free memory error in icu - CVE-2017-14952
Published: May 30, 2018
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to double free memory error in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++. A remote unauthenticated attacker can supply a ca specially crafted string, aka a "redundant UVector entry clean up function call" issue, trigger memory corruption and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
Arch Linux
IBM i
Ubuntu
Fedora
IBM DataPower Gateway
openSUSE Leap
icu
How to mitigate CVE-2017-14952
icu - addressed in versions 57.1-7.fc26, 57.1-9.fc27