libicu in International Components for Unicode (ICU) 3.8.1 and earlier attempts to process backreferences to the nonexistent capture group zero (aka 0), which might allow context-dependent attackers to read from, or write to, out-of-bounds memory locations, related to corruption of REStackFrames.
Name | Vendor | Start Version | End Version |
---|---|---|---|
International_components_for_unicode | Icu-project | * | 3.8.1 (including) |
Red Hat Enterprise Linux 5 | RedHat | icu-0:3.6-5.11.1 | * |
Icu | Ubuntu | dapper | * |
Icu | Ubuntu | edgy | * |
Icu | Ubuntu | feisty | * |
Icu | Ubuntu | gutsy | * |
Icu | Ubuntu | upstream | * |