Integer overflow in icu - CVE-2018-18928

 

Integer overflow in icu - CVE-2018-18928

Published: May 2, 2023


Vulnerability identifier: #VU75645
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-18928
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in number::impl::DecimalQuantity::toScientificString() function in i18n/number_decimalquantity.cpp. A remote attacker can pass specially crafted data to the application, trigger integer overflow and execute arbitrary code on the target system.


Affected software

icu
Log Analysis
IBM Maximo Asset Management
Fedora
Jazz Reporting Service
icu

How to mitigate CVE-2018-18928

Install updates from vendor's website.

Log Analysis - update to 1.3.8
Jazz Reporting Service - update to 7.0.2 iFix021
IBM Maximo Asset Management - update to 7.6.1.2.32
icu - update to 62.1-3.fc29

External References

Related Security Bulletins