CVE-2015-1270 PUBLISHED

The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Google Chrome before 44.0.2403.89, mishandles converter names with initial x- substrings, which allows remote attackers to cause a denial of service (read of uninitialized memory) or possibly have unspecified other impact via a crafted file.

EPSS 1.19% · 78.7th percentile

Risk Scores

EPSS Score
1.19%
78.7th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSchromium-browser0, 29.0.1547.65-0ubuntu2, 31.0.1650.63-0ubuntu1~20131204.1
Ubuntu:14.04:LTSicu0, 4.8.1.1-12ubuntu2, 4.8.1.1-13+nmu1
Ubuntu:14.04:LTSoxide-qt0, 1.0.0~bzr437-0ubuntu1, 1.0.0~bzr452-0ubuntu1

Timeline

References

Open in Interactive Console →