{"id":"USN-2605-1","summary":"icu vulnerabilities","details":"Pedro Ribeiro discovered that ICU incorrectly handled certain memory\noperations when processing data. If an application using ICU processed\ncrafted data, an attacker could cause it to crash or potentially execute\narbitrary code with the privileges of the user invoking the program.\n","modified":"2026-04-22T09:13:54.368849Z","published":"2015-05-11T14:58:23Z","related":["UBUNTU-CVE-2014-8146","UBUNTU-CVE-2014-8147"],"upstream":["CVE-2014-8146","CVE-2014-8147","UBUNTU-CVE-2014-8146","UBUNTU-CVE-2014-8147"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-2605-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-8146"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-8147"}],"affected":[{"package":{"name":"icu","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/icu@52.1-3ubuntu0.3?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"52.1-3ubuntu0.3"}]}],"versions":["4.8.1.1-12ubuntu2","4.8.1.1-13+nmu1","4.8.1.1-13+nmu1ubuntu1","52.1-3","52.1-3ubuntu0.2"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"icu-devtools","binary_version":"52.1-3ubuntu0.3"},{"binary_name":"libicu52","binary_version":"52.1-3ubuntu0.3"}]},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2014-8146","severity":[{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2014-8147","severity":[{"type":"Ubuntu","score":"medium"}]}],"ecosystem":"Ubuntu:14.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-2605-1.json"}}],"schema_version":"1.7.5"}