PublicDateAtUSN: 2016-07-25 Candidate: CVE-2016-6293 PublicDate: 2016-07-25 14:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6293 https://ubuntu.com/security/notices/USN-3227-1 Description: The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that there is a '\0' character at the end of a certain temporary array, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a call with a long httpAcceptLanguage argument. Ubuntu-Description: Notes: mdeslaur> see php's CVE-2016-6294 Bugs: https://bugs.php.net/bug.php?id=72533 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_icu: upstream: https://ssl.icu-project.org/trac/changeset/39109 upstream_icu: released (57.1-4) precise_icu: released (4.8.1.1-3ubuntu0.7) precise/esm_icu: released (4.8.1.1-3ubuntu0.7) trusty_icu: released (52.1-3ubuntu0.5) trusty/esm_icu: released (52.1-3ubuntu0.5) vivid/stable-phone-overlay_icu: ignored (reached end-of-life) vivid/ubuntu-core_icu: DNE wily_icu: ignored (reached end-of-life) xenial_icu: released (55.1-7ubuntu0.1) esm-infra/xenial_icu: released (55.1-7ubuntu0.1) yakkety_icu: not-affected (57.1-4) zesty_icu: not-affected (57.1-4) devel_icu: not-affected (57.1-4)