[ubuntu/vivid-security] icu 52.1-8ubuntu0.2 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Wed Sep 16 16:57:49 UTC 2015
icu (52.1-8ubuntu0.2) vivid-security; urgency=medium
* SECURITY UPDATE: denial of service via mishandling of converter names
with initial x- substrings
- debian/patches/CVE-2015-1270.patch: fix logic in
source/common/ucnv_io.cpp.
- CVE-2015-1270
* SECURITY UPDATE: information disclosure via overflows
- debian/patches/CVE-2015-2632.patch: properly calculate index in
source/layout/Features.cpp, check for overflows in
source/layout/LETableReference.h.
- CVE-2015-2632
* SECURITY UPDATE: denial of service and possible code execution via
overflows
- debian/patches/CVE-2015-4760.patch: check bounds in
source/layout/ContextualGlyphInsertionProc2.cpp,
source/layout/ContextualGlyphSubstProc.cpp,
source/layout/ContextualGlyphSubstProc2.cpp,
source/layout/IndicRearrangementProcessor.cpp,
source/layout/IndicRearrangementProcessor2.cpp,
use unsigned flags in source/layout/LigatureSubstProc.cpp,
source/layout/StateTables.h, properly handle errors in
source/layout/StateTableProcessor.cpp,
source/layout/StateTableProcessor2.cpp.
- CVE-2015-4760
Date: 2015-09-11 17:00:14.103732+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/icu/52.1-8ubuntu0.2
-------------- next part --------------
Sorry, changesfile not available.
More information about the Vivid-changes
mailing list