CVE Vulnerabilities

CVE-2007-4770

Published: Jan 29, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

libicu in International Components for Unicode (ICU) 3.8.1 and earlier attempts to process backreferences to the nonexistent capture group zero (aka 0), which might allow context-dependent attackers to read from, or write to, out-of-bounds memory locations, related to corruption of REStackFrames.

Affected Software

NameVendorStart VersionEnd Version
International_components_for_unicodeIcu-project*3.8.1 (including)
Red Hat Enterprise Linux 5RedHaticu-0:3.6-5.11.1*
IcuUbuntudapper*
IcuUbuntuedgy*
IcuUbuntufeisty*
IcuUbuntugutsy*
IcuUbuntuupstream*

References