Errata overview
Errata ID 34
Date 2017-05-24
Source package icu
Fixed in version 4.4.1-8.32.201705231453
Description
This update addresses the following issues:
* Unspecified vulnerability in Oracle Java SE allows remote attackers to
  affect confidentiality via unknown vectors (CVE-2015-2632)
* Unspecified vulnerability in Oracle Java SE allows remote attackers to
  affect confidentiality, integrity, and availability via unknown vectors
  (CVE-2015-4844).
* The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in
  International Components for Unicode (ICU) for C/C++ does not ensure
  that there is a '\0' character at the end of a certain temporary array,
  which allows remote attackers to cause a denial of service
  (out-of-bounds read) or possibly have unspecified other impact
  via a call with a long httpAcceptLanguage argument (CVE-2016-6293)
* buffer overflow problem in uresbund.c (CVE-2014-9911)
* stack-based buffer overflow in the Locale class via a long locale string
  (CVE-2016-7415)
* out-of-bounds write caused by a heap-based buffer overflow related to the
  utf8TextAccess function in common/utext.cpp and the utext_setNativeIndex*
  function (CVE-2017-7867)
* out-of-bounds write caused by a heap-based buffer overflow related to the
  utf8TextAccess function in common/utext.cpp and the utext_moveIndex32*
  function (CVE-2017-7868)
Additional notes
CVE ID CVE-2015-2632
CVE-2015-4844
CVE-2016-6293
CVE-2014-9911
CVE-2016-7415
CVE-2017-7867
CVE-2017-7868
UCS Bug number #41953