Lucene search

K
ibmIBMCDEA2B691FE439F348913088A1EE13862435345431B7B6ABB9912D36644B6244
HistoryJun 17, 2018 - 12:17 p.m.

Security Bulletin:OpenSource ICU4C Vulnernabilties in IBM eDiscovery Analyzer

2018-06-1712:17:39
www.ibm.com
8

0.018 Low

EPSS

Percentile

88.3%

Summary

International Components for Unicode (ICU) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the Locale class in common/locid.cpp. By sending an overly long string, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.

Vulnerability Details

CVEID: CVE-2016-7415 DESCRIPTION: International Components for Unicode (ICU) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the Locale class in common/locid.cpp. By sending an overly long string, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVSS Base Score: 7.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/117035&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)

CVEID: CVE-2016-6293 DESCRIPTION: International Components for Unicode (ICU) could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds read in the uloc_acceptLanguageFromHTTP function. An attacker could exploit this vulnerability using a call with a long httpAcceptLanguage argument to execute arbitrary code on the system. Note: This vulnerability also affect PHP.
CVSS Base Score: 9.8
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/115536&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

IBM eDiscovery Analyzer Version 2.2.2

Remediation/Fixes

Product

| VRM|Remediation
—|—|—
IBM eDiscovery Analyzer | 2.2.2| Use IBM eDiscovery Analyzer 2.2.2 Interim Fix 0004

Workarounds and Mitigations

None. Install the interim fix.

CPENameOperatorVersion
ediscovery analyzereq2.2.2