Description
The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that there is a '\0' character at the end of a certain temporary array, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a call with a long httpAcceptLanguage argument.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-615-1 | icu security update |
Debian DSA |
DSA-3725-1 | icu security update |
EUVD |
EUVD-2016-7223 | The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that there is a '\0' character at the end of a certain temporary array, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a call with a long httpAcceptLanguage argument. |
Ubuntu USN |
USN-3227-1 | ICU vulnerabilities |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T01:22:20.885Z
Reserved: 2016-07-24T00:00:00.000Z
Link: CVE-2016-6293
No data.
Status : Modified
Published: 2016-07-25T14:59:06.497
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-6293
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN