CVE-2020-10531

An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
VendorProductVersion
icu-projectinternational_components_for_unicode
𝑥
≤ 66.1
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_server
6.0
redhatenterprise_linux_workstation
6.0
googlechrome
𝑥
< 80.0.3987.122
debiandebian_linux
8.0
debiandebian_linux
9.0
debiandebian_linux
10.0
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
canonicalubuntu_linux
19.10
opensuseleap
15.1
oraclebanking_extensibility_workbench
14.3.0
oraclebanking_extensibility_workbench
14.4.0
nodejsnode.js
10.0.0 ≤
𝑥
≤ 10.12.0
nodejsnode.js
10.13.0 ≤
𝑥
< 10.21.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
icu
bullseye
67.1-7
fixed
bookworm
72.1-3
fixed
sid
72.1-5
fixed
trixie
72.1-5
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
eoan
not-affected
bionic
Fixed 80.0.3987.149-0ubuntu0.18.04.1
released
xenial
Fixed 80.0.3987.149-0ubuntu0.16.04.1
released
trusty
dne
icu
eoan
Fixed 63.2-2ubuntu0.1
released
bionic
Fixed 60.2-3ubuntu3.1
released
xenial
Fixed 55.1-7ubuntu0.5
released
trusty
Fixed 52.1-3ubuntu0.8+esm1
released
References