Executive Summary
Summary | |
---|---|
Title | icu security update |
Informations | |||
---|---|---|---|
Name | DSA-3323 | First vendor Publication | 2015-08-01 |
Vendor | Debian | Last vendor Modification | 2015-08-01 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Several vulnerabilities were discovered in the International Components for Unicode (ICU) library. CVE-2014-8146 The Unicode Bidirectional Algorithm implementation does not properly track directionally isolated pieces of text, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via crafted text. CVE-2014-8147 The Unicode Bidirectional Algorithm implementation uses an integer data type that is inconsistent with a header file, which allows remote attackers to cause a denial of service (incorrect malloc followed by invalid free) or possibly execute arbitrary code via crafted text. CVE-2015-4760 The Layout Engine was missing multiple boundary checks. These could lead to buffer overflows and memory corruption. A specially crafted file could cause an application using ICU to parse untrusted font files to crash and, possibly, execute arbitrary code. Additionally, it was discovered that the patch applied to ICU in DSA-3187-1 for CVE-2014-6585 was incomplete, possibly leading to an invalid memory access. This could allow remote attackers to disclose portion of private memory via crafted font files. For the oldstable distribution (wheezy), these problems have been fixed in version 4.8.1.1-12+deb7u3. For the stable distribution (jessie), these problems have been fixed in version 52.1-8+deb8u2. For the testing distribution (stretch), these problems have been fixed in version 52.1-10. For the unstable distribution (sid), these problems have been fixed in version 52.1-10. We recommend that you upgrade your icu packages. |
Original Source
Url : http://www.debian.org/security/2015/dsa-3323 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
50 % | CWE-189 | Numeric Errors (CWE/SANS Top 25) |
50 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:28035 | |||
Oval ID: | oval:org.mitre.oval:def:28035 | ||
Title: | Multiple vulnerabilities in current releases of the IBM® SDK,Java Technology Edition | ||
Description: | Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors reelated to 2D, a different vulnerability than CVE-2014-6591. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2014-6585 | Version: | 4 |
Platform(s): | IBM AIX 6.1 IBM AIX 7.1 | Product(s): | |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:28654 | |||
Oval ID: | oval:org.mitre.oval:def:28654 | ||
Title: | Vulnerability in IBM SDK Java JSSE affects AIX | ||
Description: | Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2015-4760 | Version: | 1 |
Platform(s): | IBM AIX 6.1 IBM AIX 7.1 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2015-09-24 | IAVM : 2015-A-0222 - Multiple Security Vulnerabilities in Apple iOS Severity : Category I - VMSKEY : V0061471 |
2015-07-16 | IAVM : 2015-A-0158 - Multiple Vulnerabilities in Oracle Java SE Severity : Category I - VMSKEY : V0061089 |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2017-09-06 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2017-1011.nasl - Type : ACT_GATHER_INFO |
2017-09-01 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2017-2318-1.nasl - Type : ACT_GATHER_INFO |
2016-08-24 | Name : The remote device is missing a vendor-supplied security patch. File : f5_bigip_SOL17173.nasl - Type : ACT_GATHER_INFO |
2016-03-14 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201603-11.nasl - Type : ACT_GATHER_INFO |
2016-03-14 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201603-14.nasl - Type : ACT_GATHER_INFO |
2016-02-29 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2016-273.nasl - Type : ACT_GATHER_INFO |
2016-02-04 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2016-0324-1.nasl - Type : ACT_GATHER_INFO |
2015-12-29 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2015-953.nasl - Type : ACT_GATHER_INFO |
2015-11-05 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2015-1915-1.nasl - Type : ACT_GATHER_INFO |
2015-10-26 | Name : The remote host contains an application that is affected by multiple vulnerab... File : itunes_12_3_0_banner.nasl - Type : ACT_GATHER_INFO |
2015-10-14 | Name : The remote Fedora host is missing a security update. File : fedora_2015-16314.nasl - Type : ACT_GATHER_INFO |
2015-10-05 | Name : The remote host is missing a Mac OS X update that fixes multiple security vul... File : macosx_10_11.nasl - Type : ACT_GATHER_INFO |
2015-09-24 | Name : The remote Fedora host is missing a security update. File : fedora_2015-16315.nasl - Type : ACT_GATHER_INFO |
2015-09-18 | Name : The remote host contains an application that is affected by multiple vulnerab... File : itunes_12_3_0.nasl - Type : ACT_GATHER_INFO |
2015-09-17 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2740-1.nasl - Type : ACT_GATHER_INFO |
2015-09-09 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2015-1509-1.nasl - Type : ACT_GATHER_INFO |
2015-08-31 | Name : The remote Debian host is missing a security update. File : debian_DLA-303.nasl - Type : ACT_GATHER_INFO |
2015-08-26 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2015-586.nasl - Type : ACT_GATHER_INFO |
2015-08-24 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3339.nasl - Type : ACT_GATHER_INFO |
2015-08-17 | Name : The remote AIX host has a version of Java SDK installed that is affected by m... File : aix_java_july2015_advisory.nasl - Type : ACT_GATHER_INFO |
2015-08-13 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-1604.nasl - Type : ACT_GATHER_INFO |
2015-08-13 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2015-1375-1.nasl - Type : ACT_GATHER_INFO |
2015-08-07 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2706-1.nasl - Type : ACT_GATHER_INFO |
2015-08-05 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-1544.nasl - Type : ACT_GATHER_INFO |
2015-08-04 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20150730_java_1_6_0_openjdk_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2015-08-04 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2015-1329-1.nasl - Type : ACT_GATHER_INFO |
2015-08-04 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2015-1331-1.nasl - Type : ACT_GATHER_INFO |
2015-08-03 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3323.nasl - Type : ACT_GATHER_INFO |
2015-07-31 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2015-1526.nasl - Type : ACT_GATHER_INFO |
2015-07-31 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2015-1526.nasl - Type : ACT_GATHER_INFO |
2015-07-31 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-1526.nasl - Type : ACT_GATHER_INFO |
2015-07-31 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2015-1319-1.nasl - Type : ACT_GATHER_INFO |
2015-07-31 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2015-1320-1.nasl - Type : ACT_GATHER_INFO |
2015-07-31 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2696-1.nasl - Type : ACT_GATHER_INFO |
2015-07-29 | Name : The remote Debian host is missing a security update. File : debian_DLA-283.nasl - Type : ACT_GATHER_INFO |
2015-07-28 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3316.nasl - Type : ACT_GATHER_INFO |
2015-07-27 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2015-511.nasl - Type : ACT_GATHER_INFO |
2015-07-27 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2015-512.nasl - Type : ACT_GATHER_INFO |
2015-07-24 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-1488.nasl - Type : ACT_GATHER_INFO |
2015-07-23 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2015-570.nasl - Type : ACT_GATHER_INFO |
2015-07-23 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2015-571.nasl - Type : ACT_GATHER_INFO |
2015-07-23 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-1485.nasl - Type : ACT_GATHER_INFO |
2015-07-23 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-1486.nasl - Type : ACT_GATHER_INFO |
2015-07-20 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-1241.nasl - Type : ACT_GATHER_INFO |
2015-07-20 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-1242.nasl - Type : ACT_GATHER_INFO |
2015-07-20 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-1243.nasl - Type : ACT_GATHER_INFO |
2015-07-17 | Name : The remote Windows host contains a programming platform that is affected by m... File : oracle_java_cpu_jul_2015.nasl - Type : ACT_GATHER_INFO |
2015-07-17 | Name : The remote Unix host contains a programming platform that is affected by mult... File : oracle_java_cpu_jul_2015_unix.nasl - Type : ACT_GATHER_INFO |
2015-07-17 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2015-1230.nasl - Type : ACT_GATHER_INFO |
2015-07-16 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2015-1228.nasl - Type : ACT_GATHER_INFO |
2015-07-16 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2015-1229.nasl - Type : ACT_GATHER_INFO |
2015-07-16 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2015-1230.nasl - Type : ACT_GATHER_INFO |
2015-07-16 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2015-1228.nasl - Type : ACT_GATHER_INFO |
2015-07-16 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2015-1229.nasl - Type : ACT_GATHER_INFO |
2015-07-16 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-1228.nasl - Type : ACT_GATHER_INFO |
2015-07-16 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-1229.nasl - Type : ACT_GATHER_INFO |
2015-07-16 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-1230.nasl - Type : ACT_GATHER_INFO |
2015-07-16 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20150715_java_1_7_0_openjdk_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2015-07-16 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20150715_java_1_7_0_openjdk_on_SL6_x.nasl - Type : ACT_GATHER_INFO |
2015-07-16 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20150715_java_1_8_0_openjdk_on_SL6_x.nasl - Type : ACT_GATHER_INFO |
2015-07-14 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201507-14.nasl - Type : ACT_GATHER_INFO |
2015-07-08 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201507-04.nasl - Type : ACT_GATHER_INFO |
2015-05-20 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2015-0503-1.nasl - Type : ACT_GATHER_INFO |
2015-05-15 | Name : The remote Debian host is missing a security update. File : debian_DLA-219.nasl - Type : ACT_GATHER_INFO |
2015-05-12 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-2605-1.nasl - Type : ACT_GATHER_INFO |
2015-05-01 | Name : The remote host has a virtualization management application installed that is... File : vmware_vcenter_vmsa-2015-0003.nasl - Type : ACT_GATHER_INFO |
2015-04-20 | Name : The remote Windows host has an application installed that is affected by mult... File : vmware_vcenter_chargeback_manager_vmsa_2015_0003.nasl - Type : ACT_GATHER_INFO |
2015-04-13 | Name : The remote Windows host has an application installed that is affected by mult... File : vmware_horizon_view_VMSA-2015-0003.nasl - Type : ACT_GATHER_INFO |
2015-04-13 | Name : The remote host has a device management application installed that is affecte... File : vmware_workspace_portal_vmsa2015-0003.nasl - Type : ACT_GATHER_INFO |
2015-04-10 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2015-198.nasl - Type : ACT_GATHER_INFO |
2015-04-10 | Name : The remote Linux host has a virtualization application installed that is miss... File : vcenter_operations_manager_vmsa_2015-0003-linux.nasl - Type : ACT_GATHER_INFO |
2015-04-10 | Name : The remote host has a virtualization application installed that is missing a ... File : vcenter_operations_manager_vmsa_2015-0003-vapp.nasl - Type : ACT_GATHER_INFO |
2015-04-10 | Name : The remote Windows host has a virtualization application installed that is mi... File : vcenter_operations_manager_vmsa_2015-0003-win.nasl - Type : ACT_GATHER_INFO |
2015-04-03 | Name : The remote Fedora host is missing a security update. File : fedora_2015-3569.nasl - Type : ACT_GATHER_INFO |
2015-03-30 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2015-161.nasl - Type : ACT_GATHER_INFO |
2015-03-26 | Name : The remote Debian host is missing a security update. File : debian_DLA-157.nasl - Type : ACT_GATHER_INFO |
2015-03-25 | Name : The remote Fedora host is missing a security update. File : fedora_2015-3590.nasl - Type : ACT_GATHER_INFO |
2015-03-17 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3187.nasl - Type : ACT_GATHER_INFO |
2015-03-11 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-2522-3.nasl - Type : ACT_GATHER_INFO |
2015-03-09 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-2522-2.nasl - Type : ACT_GATHER_INFO |
2015-03-06 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2522-1.nasl - Type : ACT_GATHER_INFO |
2015-02-25 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-0263.nasl - Type : ACT_GATHER_INFO |
2015-02-25 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-0264.nasl - Type : ACT_GATHER_INFO |
2015-02-24 | Name : The remote AIX host has a version of Java SDK installed that is affected by m... File : aix_java_feb2015_advisory.nasl - Type : ACT_GATHER_INFO |
2015-02-20 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_java-1_7_0-openjdk-150206.nasl - Type : ACT_GATHER_INFO |
2015-02-13 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2015-480.nasl - Type : ACT_GATHER_INFO |
2015-02-09 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2015-033.nasl - Type : ACT_GATHER_INFO |
2015-02-06 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-0133.nasl - Type : ACT_GATHER_INFO |
2015-02-06 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-0134.nasl - Type : ACT_GATHER_INFO |
2015-02-06 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-0135.nasl - Type : ACT_GATHER_INFO |
2015-02-06 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-0136.nasl - Type : ACT_GATHER_INFO |
2015-02-03 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2015-91.nasl - Type : ACT_GATHER_INFO |
2015-02-02 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3147.nasl - Type : ACT_GATHER_INFO |
2015-01-30 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3144.nasl - Type : ACT_GATHER_INFO |
2015-01-28 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2486-1.nasl - Type : ACT_GATHER_INFO |
2015-01-28 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2487-1.nasl - Type : ACT_GATHER_INFO |
2015-01-27 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2015-0085.nasl - Type : ACT_GATHER_INFO |
2015-01-27 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2015-0085.nasl - Type : ACT_GATHER_INFO |
2015-01-27 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-0085.nasl - Type : ACT_GATHER_INFO |
2015-01-27 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-0086.nasl - Type : ACT_GATHER_INFO |
2015-01-27 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20150126_java_1_6_0_openjdk_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2015-01-23 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2015-471.nasl - Type : ACT_GATHER_INFO |
2015-01-23 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2015-472.nasl - Type : ACT_GATHER_INFO |
2015-01-23 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-0079.nasl - Type : ACT_GATHER_INFO |
2015-01-23 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-0080.nasl - Type : ACT_GATHER_INFO |
2015-01-22 | Name : The remote Windows host contains a programming platform that is affected by m... File : oracle_java_cpu_jan_2015.nasl - Type : ACT_GATHER_INFO |
2015-01-22 | Name : The remote Unix host contains a programming platform that is affected by mult... File : oracle_java_cpu_jan_2015_unix.nasl - Type : ACT_GATHER_INFO |
2015-01-22 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2015-0067.nasl - Type : ACT_GATHER_INFO |
2015-01-22 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2015-0068.nasl - Type : ACT_GATHER_INFO |
2015-01-22 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2015-0069.nasl - Type : ACT_GATHER_INFO |
2015-01-22 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20150121_java_1_7_0_openjdk_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2015-01-22 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20150121_java_1_7_0_openjdk_on_SL6_x.nasl - Type : ACT_GATHER_INFO |
2015-01-22 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20150121_java_1_8_0_openjdk_on_SL6_x.nasl - Type : ACT_GATHER_INFO |
2015-01-21 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2015-0067.nasl - Type : ACT_GATHER_INFO |
2015-01-21 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2015-0068.nasl - Type : ACT_GATHER_INFO |
2015-01-21 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2015-0069.nasl - Type : ACT_GATHER_INFO |
2015-01-21 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-0067.nasl - Type : ACT_GATHER_INFO |
2015-01-21 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-0068.nasl - Type : ACT_GATHER_INFO |
2015-01-21 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-0069.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2015-08-12 13:33:32 |
|
2015-08-01 21:25:36 |
|