Integer overflow in icu - CVE-2020-10531
Published: March 17, 2020 / Updated: June 3, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in UnicodeString::doAppend() function in common/unistr.cpp. A remote attacker can pass specially crafted string to the application that is using the vulnerable library, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
CentOS
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
SUSE Enterprise Storage
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
Opensuse
openSUSE Leap
IBM Cloud Transformation Advisor
Oracle VM Server for x86
IBM Rational ClearQuest
icu (Alpine package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
rh-nodejs10-nodejs (Red Hat package)
icu (Ubuntu package)
icu (Debian package)
rh-nodejs12-nodejs (Red Hat package)
nodejs
icu (Red Hat package)
icu73_2-debugsource
libicu73_2-bedata
libicu73_2-ledata
libicu73_2-doc
libicu73_2-devel
libicu73_2-debuginfo
libicu73_2
icu73_2-debuginfo
icu73_2
chromium
Node.js
IBM DataPower Gateway
Red Hat OpenShift Container Platform
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
How to mitigate CVE-2020-10531
icu (Alpine package) - update to 60.2-r3
Node.js - update to 10.21.0
IBM DataPower Gateway - addressed in versions 10.0.1.5, 10.0.4.0, 2018.4.1.18
rh-nodejs10-nodejs (Red Hat package) - update to 10.21.0-3.el7
icu (Ubuntu package) - addressed in versions 55.1-7ubuntu0.5, 60.2-3ubuntu3.1, 63.2-2ubuntu0.1
icu (Debian package) - addressed in versions 57.1-6+deb9u4, 63.1-6+deb10u1
Red Hat OpenShift Container Platform - update to 4.5.8
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
EMC ViPR SRM - update to 4.9.0.0
Dell EMC Unity Operating Environment (OE) - update to 5.0.4.0.5.012
Dell EMC Unity XT Operating Environment (OE) - update to 5.0.4.0.5.012
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.4.0.5.012
IBM Rational ClearQuest - update to 10.0.6
rh-nodejs12-nodejs (Red Hat package) - update to 12.18.2-1.el7
nodejs - addressed in versions 14.15.1-1.fc33, 14-3220201203015508.43bbeeef, 14-3320201203015508.601d93de
icu (Red Hat package) - addressed in versions 60.3-2.el8_0, 60.3-2.el8_1
icu73_2-debugsource - update to 73.2-150000.1.3.1
libicu73_2-bedata - update to 73.2-150000.1.3.1
libicu73_2-ledata - update to 73.2-150000.1.3.1
libicu73_2-doc - update to 73.2-150000.1.3.1
libicu73_2-devel - update to 73.2-150000.1.3.1
libicu73_2-debuginfo - update to 73.2-150000.1.3.1
libicu73_2 - update to 73.2-150000.1.3.1
icu73_2-debuginfo - update to 73.2-150000.1.3.1
icu73_2 - update to 73.2-150000.1.3.1
chromium - addressed in versions 80.0.3987.132-1.el8, 80.0.3987.132-1.fc30, 80.0.3987.132-1.fc31, 80.0.3987.149-1.el8, 80.0.3987.149-1.fc30, 80.0.3987.162-1.el8, 80.0.3987.163-1.el8, 81.0.4044.113-1.el8, 81.0.4044.113-2.el8, 81.0.4044.122-1.el8, 81.0.4044.138-1.el8
External References
- https://access.redhat.com/errata/RHSA-2020:0738
- https://bugs.chromium.org/p/chromium/issues/detail?id=1044570
- https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_24.html
- https://chromium.googlesource.com/chromium/deps/icu/+/9f4020916eb1f28f3666f018fdcbe6c9a37f0e08
- https://github.com/unicode-org/icu/commit/b7d08bc04a4296982fcef8b6b8a354a9e4e7afca
- https://github.com/unicode-org/icu/pull/971
- https://security.gentoo.org/glsa/202003-15
Related Security Bulletins
- Gentoo update for ICU
- Integer overflow in International Components for Unicode (ICU)
- Ubuntu update for ICU
- Red Hat Enterprise Linux 6 update for icu
- Red Hat Enterprise Linux 7 update for icu
- Debian update for icu
- CentOS 6 update for icu
- CentOS 7 update for icu
- Red Hat Enterprise Linux 8 update for the nodejs:12 module
- OpenSUSE Linux update for icu
- Red Hat Enterprise Linux 8 update for the nodejs:10 module
- Red Hat Enterprise Linux 8 update for the nodejs:10 module
- Multiple vulnerabilities in Oracle VM Server
- Amazon Linux AMI update for icu
- Multiple vulnerabilities in Node.js
- Red Hat Software Collections update for rh-nodejs10-nodejs
- Integer overflow in icu (Alpine package)
- Multiple vulnerabilities in IBM DataPower Gateway Virtual Edition
- Integer overflow in Dell EMC Unity
- Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions update for icu
- Red Hat Enterprise Linux 8 update for icu
- Red Hat Software Collections update for rh-nodejs12-nodejs
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)
- SUSE update for icu73_2
- SUSE update for icu73_2
- SUSE update for icu73_2
- Multiple vulnerabilities in IBM Rational ClearQuest
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.5
- Fedora EPEL 8 update for chromium
- Fedora 31 update for chromium
- Fedora 30 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora 30 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora 32 Modular update for nodejs
- Fedora 33 Modular update for nodejs
- Fedora 33 update for nodejs