Back

MEDIUM

libicu poor back reference validation

Published Jan 28, 2008

Description

libicu in International Components for Unicode (ICU) 3.8.1 and earlier attempts to process backreferences to the nonexistent capture group zero (aka \0), which might allow context-dependent attackers to read from, or write to, out-of-bounds memory locations, related to corruption of REStackFrames.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (43)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 28, 2008
Updated Aug 7, 2024
Reserved Sep 10, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Jan 22, 2008