CVE-2017-17484
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The ucnv_UTF8FromUTF8 function in ucnv_u8.cpp in International Components for Unicode (ICU) for C/C++ through 60.1 mishandles ucnv_convertEx calls for UTF-8 to UTF-8 conversion, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted string, as demonstrated by ZNC.
La función ucnv_UTF8FromUTF8 en ucnv_u8.cpp en International Components for Unicode (ICU) para C/C++ hasta la versión 60.1 gestiona de manera incorrecta las llamadas ucnv_convertEx para la conversión UTF-8 a UTF-8. Esto permite que atacantes remotos provoquen una denegación de servicio (desbordamiento de búfer basado en pila y cierre inesperado de la aplicación) o, posiblemente, causen otro impacto sin especificar mediante una cadena manipulada, tal y como demuestra ZNC.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-12-10 CVE Reserved
- 2017-12-10 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
https://github.com/znc/znc/issues/1459 | Issue Tracking | |
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html | X_refsource_misc |
URL | Date | SRC |
---|---|---|
https://ssl.icu-project.org/trac/attachment/ticket/13490/poc.cpp | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://ssl.icu-project.org/trac/changeset/40714 | 2019-04-23 |
URL | Date | SRC |
---|---|---|
https://ssl.icu-project.org/trac/changeset/40715 | 2019-04-23 | |
https://ssl.icu-project.org/trac/ticket/13490 | 2019-04-23 | |
https://ssl.icu-project.org/trac/ticket/13510 | 2019-04-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Icu-project Search vendor "Icu-project" | International Components For Unicode Search vendor "Icu-project" for product "International Components For Unicode" | <= 60.1 Search vendor "Icu-project" for product "International Components For Unicode" and version " <= 60.1" | c\/c\+\+ |
Affected
|