Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Fri, 09 Dec 2011 09:31:06 +0100
From: Ludwig Nussel <>
Subject: CVE Request: icu out of bounds access


An of bounds access was reported in icu:

Unfortunately the chrome bug is private but the commit says "buffer

I suppose a negative len could end up in the strncpy at the end of the
function causing a buffer overflow.


 (o_   Ludwig Nussel
SUSE LINUX Products GmbH, GF: Jeff Hawn, Jennifer Guild, Felix Imend├Ârffer, HRB 16746 (AG N├╝rnberg) 

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.