MAGEIA-2015-286
The ICU Project's ICU4C library, before 55.1, contains a heap-based buffer overflow in the resolveImplicitLevels function of ubidi.c (CVE-2014-8146). The ICU Project's ICU4C library, before 55.1, contains an integer overflow in the resolveImplicitLevels function of ubidi.c due to the assignment of an int32 value to an int16 type (CVE-2014-8147). The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU) mishandles converter names with initial x- substrings, which allows remote attackers to cause a denial of service (read of uninitialized memory) or possibly have unspecified other impact via a crafted file (CVE-2015-1270).
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mageia | icu | 52.1-2.4.mga4, 0 |
Timeline
- Jul 27, 2015 CVE Updated
- Jul 27, 2015 CVE Published
- Mar 17, 2026 Security Advisory