CVE-2011-4599

Stack-based buffer overflow in the _canonicalize function in common/uloc.c in International Components for Unicode (ICU) before 49.1 allows remote attackers to execute arbitrary code via a crafted locale ID that is not properly handled during variant canonicalization.
Configurations

Configuration 1 (hide)

cpe:2.3:a:icu-project:international_components_for_unicode:*:*:*:*:*:c\/c\+\+:*:*

History

13 Feb 2023, 03:23

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2011-4599', 'name': 'https://access.redhat.com/security/cve/CVE-2011-4599', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=765812', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=765812', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2011:1815', 'name': 'https://access.redhat.com/errata/RHSA-2011:1815', 'tags': [], 'refsource': 'MISC'}
Summary CVE-2011-4599 icu: Stack-based buffer overflow by canonicalizing the given localeID Stack-based buffer overflow in the _canonicalize function in common/uloc.c in International Components for Unicode (ICU) before 49.1 allows remote attackers to execute arbitrary code via a crafted locale ID that is not properly handled during variant canonicalization.

02 Feb 2023, 18:15

Type Values Removed Values Added
Summary Stack-based buffer overflow in the _canonicalize function in common/uloc.c in International Components for Unicode (ICU) before 49.1 allows remote attackers to execute arbitrary code via a crafted locale ID that is not properly handled during variant canonicalization. CVE-2011-4599 icu: Stack-based buffer overflow by canonicalizing the given localeID
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2011-4599 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=765812 -
  • (MISC) https://access.redhat.com/errata/RHSA-2011:1815 -

Information

Published : 2012-06-21 15:55

Updated : 2023-12-10 11:16


NVD link : CVE-2011-4599

Mitre link : CVE-2011-4599

CVE.ORG link : CVE-2011-4599


JSON object : View

Products Affected

icu-project

  • international_components_for_unicode
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer