Univention Bugzilla – Bug 46768
icu: Multiple issues (4.2)
Last modified: 2018-04-18 14:16:02 CEST
New Debian icu 52.1-8+deb8u7 fixes: This update addresses the following issue: * CVE_2017-15422: Fix Persian calendar integer overflow. CVE-2017-15422 chromium-browser: integer overflow in icu
[4.2-3] 0b78db638e Bug #46768: icu_52.1-8+deb8u7
Advisory is missing issues fixed since 52.1-8+deb8u4: * Backport upstream security fix for CVE-2017-14952: double free in createMetazoneMappings() (closes: #878840). * Backport upstream security fix for CVE-2017-7867 and CVE-2017-7868, heap-buffer-overflow in utf8TextAccess. Otherwise verified: * Upstream binary imported into errata4.2-3 * No additional UCS patches in 4.2
(In reply to Arvid Requate from comment #2) > Advisory is missing issues fixed since 52.1-8+deb8u4: > > * Backport upstream security fix for CVE-2017-14952: double free in > createMetazoneMappings() (closes: #878840). > > * Backport upstream security fix for CVE-2017-7867 and CVE-2017-7868, > heap-buffer-overflow in utf8TextAccess. deb8u6 was already imported and released for errata4.2-3: <https://forge.univention.org/bugzilla/show_bug.cgi?id=44415> <http://errata.software-univention.de/ucs/4.2/247.html> <http://xen1.knut.univention.de:8000/packages/source/icu/?since=4.2&before=4.3> So this is only the one mentioned CVE. Nothing more to do from my side.
Ok, thanks!
<http://errata.software-univention.de/ucs/4.2/335.html>