Unrated severityNVD Advisory· Published May 25, 2015· Updated May 6, 2026
CVE-2014-8146
CVE-2014-8146
Description
The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 does not properly track directionally isolated pieces of text, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via crafted text.
Affected products
5- cpe:2.3:a:icu-project:international_components_for_unicode:*:*:*:*:*:c\/c\+\+:*:*Range: <55.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
19- www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlnvdPatch
- seclists.org/fulldisclosure/2015/May/14nvdExploitMailing ListThird Party Advisory
- raw.githubusercontent.com/pedrib/PoC/master/generic/i-c-u-fail.txtnvdExploit
- bugs.icu-project.org/trac/changeset/37162nvdIssue TrackingVendor Advisory
- www.debian.org/security/2015/dsa-3323nvdThird Party Advisory
- www.kb.cert.org/vuls/id/602540nvdThird Party AdvisoryUS Government Resource
- www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlnvdThird Party Advisory
- www.securityfocus.com/bid/74457nvdThird Party AdvisoryVDB Entry
- security.gentoo.org/glsa/201507-04nvdThird Party Advisory
- support.apple.com/HT205212nvdThird Party Advisory
- support.apple.com/HT205213nvdThird Party Advisory
- support.apple.com/HT205221nvdThird Party Advisory
- support.apple.com/HT205267nvdThird Party Advisory
- lists.apple.com/archives/security-announce/2015/Sep/msg00001.htmlnvdMailing List
- lists.apple.com/archives/security-announce/2015/Sep/msg00003.htmlnvdMailing List
- lists.apple.com/archives/security-announce/2015/Sep/msg00005.htmlnvdMailing List
- lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlnvdMailing List
- openwall.com/lists/oss-security/2015/05/05/6nvdMailing List
- www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlnvd
News mentions
0No linked articles in our index yet.