{"id":"MGASA-2015-0297","summary":"Updated icu package fixes security vulnerability","details":"It was discovered that ICU Layout Engine was missing multiple boundary\nchecks. These could lead to buffer overflows memory corruption. A\nspecially crafted file could cause an application using ICU to parse\nuntrusted font files to crash and, possibly, execute arbitrary code\n(CVE-2015-4760).\n","modified":"2026-04-16T01:45:57.227383864Z","published":"2015-07-31T22:46:26Z","upstream":["CVE-2015-4760"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0297.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=16487"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1242447"},{"type":"WEB","url":"http://lwn.net/Alerts/652632/"}],"affected":[{"package":{"name":"icu","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/icu?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"52.1-2.5.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0297.json"}},{"package":{"name":"icu","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/icu?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"53.1-12.2.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0297.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}