]> code.ossystems Code Review - openembedded-core.git/commit
icu: CVE-2014-8146-CVE-2014-8147
authorSona Sarmadi <sona.sarmadi@enea.com>
Fri, 28 Aug 2015 13:12:04 +0000 (15:12 +0200)
committerJoshua Lock <joshua.lock@collabora.co.uk>
Tue, 1 Sep 2015 11:36:15 +0000 (12:36 +0100)
commita461a1a9141fb6a3f79bf9773a837daace2e9996
treed34a6fca10e5faa4835d215e13ad07e7bba2b690
parentbda086118abfb168183dc285357ecbb6dccff5e3
icu: CVE-2014-8146-CVE-2014-8147

CVE-2014-8146 icu: heap overflow via incorrect isolateCount
CVE-2014-8147 icu: integer truncation in the resolveImplicitLevels function

References:
[1] https://github.com/pedrib/PoC/raw/master/generic/i-c-u-fail.7z
[2] https://www.kb.cert.org/vuls/id/602540
[3] http://bugs.icu-project.org/trac/changeset/37080
[4] http://bugs.icu-project.org/trac/changeset/37162

Signed-off-by: Sona Sarmadi <sona.sarmadi@enea.com>
Signed-off-by: Joshua Lock <joshua.lock@collabora.co.uk>
meta/recipes-support/icu/icu/icu-CVE-2014-8146-CVE-2014-8147.patch [new file with mode: 0644]
meta/recipes-support/icu/icu_54.1.bb