Use-after-free in icu - CVE-2020-21913
Published: November 29, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error within the pkg_createWithAssemblyCode() function in the file tools/pkgdata/pkgdata.cpp. A remote attacker can trick the victim to open a specially crafted file and perform a denial of service (DoS) attack.
Affected software
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
WD Cloud
My Cloud EX2100
My Cloud DL4100
My Cloud DL2100
My Cloud Mirror Gen 2
My Cloud EX2 Ultra
My Cloud EX4100
My Cloud PR4100
My Cloud PR2100
My Cloud
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Storage
SUSE Enterprise Storage
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Desktop
Ubuntu
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Module for Legacy Software
Basesystem Module
openSUSE Leap
openEuler
My Cloud OS 5
SUSE Linux Enterprise Module for Packagehub Subpackages
icu (Debian package)
libicu52 (Ubuntu package)
libicu52_1-debuginfo-32bit
libicu52_1-32bit
icu
icu-debuginfo
icu-debugsource
libicu-devel
libicu-doc
libicu52_1
libicu52_1-data
libicu52_1-debuginfo
libicu55 (Ubuntu package)
libicu60 (Ubuntu package)
libiculx60 (Ubuntu package)
icu-devtools (Ubuntu package)
libicu60_2
libicu60_2-debuginfo
libicu60_2-32bit
libicu60_2-32bit-debuginfo
libicu60_2-bedata
libicu60_2-ledata
libicu
icu-help
libicu-suse65_1
libicu-suse65_1-debuginfo
libicu65_1-ledata
libicu-devel-32bit
libicu-suse65_1-32bit
libicu-suse65_1-32bit-debuginfo
libicu65_1-bedata
libicu73_2-ledata
libicu73_2-bedata
libicu73_2-doc
libicu73_2-devel
icu73_2-debugsource
libicu73_2
icu73_2-debuginfo
libicu73_2-debuginfo
icu73_2
Dell EMC NetWorker vProxy
How to mitigate CVE-2020-21913
icu (Debian package) - update to 63.1-6+deb10u2
Dell EMC NetWorker vProxy - update to 4.3.0-36
My Cloud OS 5 - update to 5.19.117
libicu52 (Ubuntu package) - update to 52.1-3ubuntu0.8
libicu52_1-debuginfo-32bit - update to 52.1-8.13.1
libicu52_1-32bit - update to 52.1-8.13.1
icu - addressed in versions 52.1-8.13.1, 65.1-150200.4.5.1
icu-debuginfo - addressed in versions 52.1-8.13.1, 60.2-150000.3.12.1, 65.1-150200.4.5.1
icu-debugsource - addressed in versions 52.1-8.13.1, 60.2-150000.3.12.1, 65.1-150200.4.5.1
libicu-devel - addressed in versions 52.1-8.13.1, 65.1-150200.4.5.1
libicu-doc - addressed in versions 52.1-8.13.1, 65.1-150200.4.5.1
libicu52_1 - update to 52.1-8.13.1
libicu52_1-data - update to 52.1-8.13.1
libicu52_1-debuginfo - update to 52.1-8.13.1
libicu55 (Ubuntu package) - update to 55.1-7
libicu60 (Ubuntu package) - update to 60.2-3ubuntu3.2
libiculx60 (Ubuntu package) - update to 60.2-3ubuntu3.2
icu-devtools (Ubuntu package) - update to 60.2-3ubuntu3.2
libicu60_2 - update to 60.2-150000.3.12.1
libicu60_2-debuginfo - update to 60.2-150000.3.12.1
libicu60_2-32bit - update to 60.2-150000.3.12.1
libicu60_2-32bit-debuginfo - update to 60.2-150000.3.12.1
libicu60_2-bedata - update to 60.2-150000.3.12.1
libicu60_2-ledata - update to 60.2-150000.3.12.1
libicu-devel - update to 62.1-6
icu-debugsource - update to 62.1-6
icu-debuginfo - update to 62.1-6
libicu - update to 62.1-6
icu - update to 62.1-6
icu-help - update to 62.1-6
libicu-suse65_1 - update to 65.1-150200.4.5.1
libicu-suse65_1-debuginfo - update to 65.1-150200.4.5.1
libicu65_1-ledata - update to 65.1-150200.4.5.1
libicu-devel-32bit - update to 65.1-150200.4.5.1
libicu-suse65_1-32bit - update to 65.1-150200.4.5.1
libicu-suse65_1-32bit-debuginfo - update to 65.1-150200.4.5.1
libicu65_1-bedata - update to 65.1-150200.4.5.1
libicu73_2-ledata - update to 73.2-150000.1.3.1
libicu73_2-bedata - update to 73.2-150000.1.3.1
libicu73_2-doc - update to 73.2-150000.1.3.1
libicu73_2-devel - update to 73.2-150000.1.3.1
icu73_2-debugsource - update to 73.2-150000.1.3.1
libicu73_2 - update to 73.2-150000.1.3.1
icu73_2-debuginfo - update to 73.2-150000.1.3.1
libicu73_2-debuginfo - update to 73.2-150000.1.3.1
icu73_2 - update to 73.2-150000.1.3.1
External References
Related Security Bulletins
- Denial of service in International Components for Unicode
- Debian update for icu
- Denial of service in Western Digital My Cloud OS 5
- Ubuntu update for icu
- SUSE update for icu
- SUSE update for icu
- SUSE update for icu
- Multiple vulnerabilities in Dell EMC Data Protection Central
- Multiple vulnerabilities in Dell NetWorker vProxy
- SUSE update for icu73_2
- SUSE update for icu73_2
- SUSE update for icu73_2
- openEuler update for icu