Back

HIGH

ICU: regexp engine missing look-behind expression range check

Published Jan 22, 2015

Description

The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a look-behind expression.

Affected products

Remediation

Red Hat statement

The flaw is caused because the ICU regular expression compiler is unable to properly handle certain malformed patterns. Because of the way in which this flaw manifests itself, it can only be triggered via untrusted content, which is common for components such as web browsers, in this case, the Chromium browser. This flaw has been rated moderate for ICU component in Red Hat products, because either it is very difficult to trigger this flaw, or it is unusual to directly pass untrusted parameters to the ICU library.

Metrics

Weaknesses (2)

References (24)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Jan 22, 2015
Updated Aug 6, 2024
Reserved Oct 6, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jan 21, 2015