International Components for Unicode Library (libicu) Multiple Memory Corruption Vulnerabilities
BID:27455
Info
International Components for Unicode Library (libicu) Multiple Memory Corruption Vulnerabilities
| Bugtraq ID: | 27455 |
| Class: | Unknown |
| CVE: |
CVE-2007-4770 CVE-2007-4771 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 25 2008 12:00AM |
| Updated: | Apr 13 2015 10:04PM |
| Credit: | Will Drewry is credited with the discovery of these issues. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise SDK 10 SP1 SuSE SUSE Linux Enterprise SDK 10 SuSE Suse Linux Enterprise Desktop 10 SP1 SuSE Suse Linux Enterprise Desktop 10 SuSE SUSE Linux Enterprise 10 SP1 DEBUGINFO SuSE Linux Desktop 1.0 SuSE Linux Desktop 10 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc SuSE Linux 10.0 x86-64 SuSE Linux 10.0 x86 SuSE Linux 10.0 ppc Sun StarOffice 8.0 Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 10_x86 Sun Solaris 10_sparc S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SuSE Linux Open-Xchange 4.1 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. openSUSE 10.1 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Open-Enterprise-Server 1 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop SDK 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.2 X86 64 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.2 X86 64 S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 rPath rPath Linux 1 Redhat Fedora 7 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server OpenOffice OpenOffice 2.3.1 OpenOffice OpenOffice 2.3 OpenOffice OpenOffice 2.2.1 OpenOffice OpenOffice 2.2 OpenOffice OpenOffice 2.0.4 OpenOffice OpenOffice 2.0.3 -1 OpenOffice OpenOffice 2.0.3 OpenOffice OpenOffice 2.0.2 OpenOffice OpenOffice 2.0.1 OpenOffice OpenOffice 2.0 Beta OpenOffice OpenOffice 2.2 OpenOffice OpenOffice 2.1 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri CTX 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service - CCSS7 0 Nortel Networks Multiservice Switch - MDM 0 Nortel Networks Enterprise Network Management System Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 ICU Project International Components for Unicode 3.8.1 ICU Project International Components for Unicode 3.8 ICU Project International Components for Unicode 3.6 ICU Project International Components for Unicode 0 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
OpenOffice OpenOffice 2.4 |
Discussion
Exploit / POC
International Components for Unicode Library (libicu) Multiple Memory Corruption Vulnerabilities
Currently we are not aware of any working exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
References
International Components for Unicode Library (libicu) Multiple Memory Corruption Vulnerabilities
References:
References:
- [icu-support] ICU Patch for bugs in Regular Expressions (ICU Project)
- Bugzilla Bug 429023: CVE-2007-4770 libicu poor back reference validation (Red Hat)
- Bugzilla Bug 429025: CVE-2007-4771 libicu incomplete interval handling (Red Hat)
- ICU Project Home Page (ICU Project)
- 2008008820: Nortel response to Sun Alert 233922 - Multiple Security Vulnerabilit (Nortel Networks)
- 231641: Security Vulnerability for ODF Text Documents Containing XForms in StarO (Sun)
- 233922 Multiple Security Vulnerabilities in ICU 3.2 Library Regular Expression P (Sun)
- CVE-2007-4770/4771 - Manipulated ODF text documents containing XForms can lead t (OpenOffice)
- RHSA-2008:0090-4: icu security updatea (Red Hat)