CVE-2016-6293

The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that there is a '\0' character at the end of a certain temporary array, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a call with a long httpAcceptLanguage argument.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
Affected Products (NVD)
VendorProductVersion
icu-projectinternational_components_for_unicode
𝑥
≤ 57.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
icu
bookworm
72.1-3
fixed
bullseye
67.1-7
fixed
sid
72.1-5
fixed
trixie
72.1-5
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
icu
precise
Fixed 4.8.1.1-3ubuntu0.7
released
trusty
Fixed 52.1-3ubuntu0.5
released
wily
ignored
xenial
Fixed 55.1-7ubuntu0.1
released
yakkety
not-affected
zesty
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libicu-doc
suse enterprise sap 12 SP1
52.1-8.7.1
fixed
suse enterprise sap 12 SP2
52.1-8.7.1
fixed
suse enterprise sap 12 SP3
52.1-8.7.1
fixed
suse enterprise sap 12 SP5
52.1-8.7.1
fixed
suse enterprise server 12
52.1-8.7.1
fixed
suse enterprise server 12 SP1
52.1-8.7.1
fixed
suse enterprise server 12 SP2
52.1-8.7.1
fixed
suse enterprise server 12 SP3
52.1-8.7.1
fixed
suse enterprise server 12 SP4
52.1-8.7.1
fixed
suse enterprise server 12 SP5
52.1-8.7.1
fixed
libicu52_1
suse enterprise sap 12 SP1
52.1-8.7.1
fixed
suse enterprise sap 12 SP2
52.1-8.7.1
fixed
suse enterprise sap 12 SP3
52.1-8.7.1
fixed
suse enterprise sap 12 SP5
52.1-8.7.1
fixed
suse enterprise server 12
52.1-8.7.1
fixed
suse enterprise server 12 SP1
52.1-8.7.1
fixed
suse enterprise server 12 SP2
52.1-8.7.1
fixed
suse enterprise server 12 SP3
52.1-8.7.1
fixed
suse enterprise server 12 SP4
52.1-8.7.1
fixed
suse enterprise server 12 SP5
52.1-8.7.1
fixed
libicu52_1-32bit
suse enterprise sap 12 SP1
52.1-8.7.1
fixed
suse enterprise sap 12 SP2
52.1-8.7.1
fixed
suse enterprise sap 12 SP3
52.1-8.7.1
fixed
suse enterprise sap 12 SP5
52.1-8.7.1
fixed
suse enterprise server 12
52.1-8.7.1
fixed
suse enterprise server 12 SP1
52.1-8.7.1
fixed
suse enterprise server 12 SP2
52.1-8.7.1
fixed
suse enterprise server 12 SP3
52.1-8.7.1
fixed
suse enterprise server 12 SP4
52.1-8.7.1
fixed
suse enterprise server 12 SP5
52.1-8.7.1
fixed
libicu52_1-data
suse enterprise sap 12 SP1
52.1-8.7.1
fixed
suse enterprise sap 12 SP2
52.1-8.7.1
fixed
suse enterprise sap 12 SP3
52.1-8.7.1
fixed
suse enterprise sap 12 SP5
52.1-8.7.1
fixed
suse enterprise server 12
52.1-8.7.1
fixed
suse enterprise server 12 SP1
52.1-8.7.1
fixed
suse enterprise server 12 SP2
52.1-8.7.1
fixed
suse enterprise server 12 SP3
52.1-8.7.1
fixed
suse enterprise server 12 SP4
52.1-8.7.1
fixed
suse enterprise server 12 SP5
52.1-8.7.1
fixed