Description
Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8 in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4150-1 | icu security update |
EUVD |
EUVD-2017-6874 | Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8 in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. |
Ubuntu USN |
USN-3610-1 | ICU vulnerability |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Google
Subscribe
Chrome
Subscribe
Icu-project
Subscribe
International Components For Unicode
Subscribe
Redhat
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Workstation
Subscribe
Rhel Extras
Subscribe
Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2024-08-05T19:57:25.992Z
Reserved: 2017-10-17T00:00:00.000Z
Link: CVE-2017-15422
No data.
Status : Modified
Published: 2018-08-28T19:29:11.520
Modified: 2024-11-21T03:14:40.320
Link: CVE-2017-15422
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN