8.8

CVE-2020-10531

An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Icu-project ≫ International Components For Unicode SwPlatform c/c++ Version <= 66.1
Google ≫ Chrome Version < 80.0.3987.122
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 31
Fedoraproject ≫ Fedora Version 33
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.10
Opensuse ≫ Leap Version 15.1
Nodejs ≫ Node.Js SwEdition - Version >= 10.0.0 <= 10.12.0
Nodejs ≫ Node.Js SwEdition lts Version >= 10.13.0 < 10.21.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.67% 0.838
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-190 Integer Overflow or Wraparound

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://www.oracle.com/security-alerts/cpujan2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html
Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html
Third Party Advisory
Not Applicable
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6IOHSO6BUKC6I66J5PZOMAGFVJ66ZS57/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3B5RWJQD5LA45MYLLR55KZJOJ5NVZGP/
https://access.redhat.com/errata/RHSA-2020:0738
Third Party Advisory
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_24.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00004.html
Third Party Advisory
Mailing List
https://bugs.chromium.org/p/chromium/issues/detail?id=1044570
Third Party Advisory
Permissions Required
https://chromium.googlesource.com/chromium/deps/icu/+/9f4020916eb1f28f3666f018fdcbe6c9a37f0e08
Patch
Third Party Advisory
https://github.com/unicode-org/icu/commit/b7d08bc04a4296982fcef8b6b8a354a9e4e7afca
Patch
Third Party Advisory
https://github.com/unicode-org/icu/pull/971
Patch
Third Party Advisory
Issue Tracking
https://lists.debian.org/debian-lts-announce/2020/03/msg00024.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4OOYAMJVLLCLXDTHW3V5UXNULZBBK4O6/
https://security.gentoo.org/glsa/202003-15
Third Party Advisory
https://unicode-org.atlassian.net/browse/ICU-20958
Third Party Advisory
Permissions Required
https://usn.ubuntu.com/4305-1/
Third Party Advisory
https://www.debian.org/security/2020/dsa-4646
Third Party Advisory