CVE-2014-9654
icu: insufficient size limit checks in regular expression compiler
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-12-03, as used in Google Chrome before 40.0.2214.91, calculates certain values without ensuring that they can be represented in a 24-bit field, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted string, a related issue to CVE-2014-7923.
El paquete Regular Expressions en International Components para Unicode (ICU) for C/C++ en las versiones anteriores a 03-12-2014, como se utiliza en Google Chrome en versiones anteriores a 40.0.2214.91, calcula ciertos valores sin asegurarse de que pueden representarse en un campo de 24 bits, que permite a atacantes remotos causar una denegación de servicio (corrupción de memoria) o posiblemente tener otro impacto no especificado a través de una cadena manipulada, un problema relacionado con CVE-2014-7923.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-02-05 CVE Reserved
- 2015-03-05 CVE Published
- 2024-07-25 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://bugs.icu-project.org/trac/changeset/36801 | Issue Tracking | |
http://openwall.com/lists/oss-security/2015/02/05/15 | Mailing List | |
http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html | X_refsource_confirm | |
http://www.securitytracker.com/id/1035410 | Third Party Advisory | |
https://chromium.googlesource.com/chromium/deps/icu/+/dd727641e190d60e4593bcb3a35c7f51eb4925c5 | Issue Tracking | |
https://code.google.com/p/chromium/issues/detail?id=432209 | Issue Tracking | |
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://bugs.icu-project.org/trac/ticket/11371 | 2019-04-23 | |
https://security.gentoo.org/glsa/201503-06 | 2019-04-23 | |
https://access.redhat.com/security/cve/CVE-2014-9654 | 2015-01-27 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1190129 | 2015-01-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | <= 40.0.2214.85 Search vendor "Google" for product "Chrome" and version " <= 40.0.2214.85" | - |
Affected
| ||||||
Icu-project Search vendor "Icu-project" | International Components For Unicode Search vendor "Icu-project" for product "International Components For Unicode" | < 55.1 Search vendor "Icu-project" for product "International Components For Unicode" and version " < 55.1" | c\/c\+\+ |
Affected
|