CVE-2011-4599
icu - buffer underflow
EPSS 8.0%
描述
Stack-based buffer overflow in the _canonicalize function in common/uloc.c in International Components for Unicode (ICU) before 49.1 allows remote attackers to execute arbitrary code via a crafted locale ID that is not properly handled during variant canonicalization.
如何修補 CVE-2011-4599
要修補 CVE-2011-4599,請將受影響套件升級到下列已修補版本。
- Debian/icu—升級至 4.8.1.1-3 或更新版本
- Debian/icu—升級至 4.4.1-8 或更新版本
CVE-2011-4599 正在被利用嗎?
中等 — EPSS 為 8.0%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 4.8.1.1-3
- from 0, < 4.4.1-8