PublicDateAtUSN: 2016-09-17 Candidate: CVE-2016-7415 PublicDate: 2016-09-17 21:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7415 http://www.openwall.com/lists/oss-security/2016/09/15/10 http://source.icu-project.org/repos/icu/icu/trunk/source/common/locid.cpp https://ubuntu.com/security/notices/USN-3227-1 Description: Stack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long locale string. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_icu: upstream_icu: released (57.1-5) precise_icu: released (4.8.1.1-3ubuntu0.7) precise/esm_icu: released (4.8.1.1-3ubuntu0.7) trusty_icu: released (52.1-3ubuntu0.5) trusty/esm_icu: released (52.1-3ubuntu0.5) vivid/stable-phone-overlay_icu: ignored (reached end-of-life) vivid/ubuntu-core_icu: DNE xenial_icu: released (55.1-7ubuntu0.1) esm-infra/xenial_icu: released (55.1-7ubuntu0.1) yakkety_icu: released (57.1-4ubuntu0.1) zesty_icu: not-affected (57.1-5) devel_icu: not-affected (57.1-5)