| Errata ID | 364 | 
|---|---|
| Date | 2016-12-21 | 
| Source package | icu | 
| Fixed in version | 4.8.1.1-12.26.201612191333 | 
| Description | This update addresses the following issues: * Unspecified vulnerability in Oracle Java SE allows remote attackers to affect confidentiality via unknown vectors (CVE-2015-2632) * Unspecified vulnerability in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors (CVE-2015-4844). * Unspecified vulnerability in the Java SE allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors (CVE-2016-0494) * The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) for C/C++ does not ensure that there is a '\0' character at the end of a certain temporary array, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a call with a long httpAcceptLanguage argument (CVE-2016-6293) * buffer overflow problem in uresbund.c (CVE-2014-9911) * stack-based buffer overflow in the Locale class via a long locale string (CVE-2016-7415)  | 
				
| Additional notes | |
| CVE ID | CVE-2015-2632 CVE-2015-4844 CVE-2016-0494 CVE-2016-6293 CVE-2014-9911 CVE-2016-7415  | 
  
| UCS Bug number | #41952 | 
