Synopsis :
These remote packages are missing security patches :
- icu-doc
- lib32icu-dev
- lib32icu38
- libicu-dev
- libicu38
- libicu38-dbg
Description :
It was discovered that ICU did not properly handle invalid byte sequences
during Unicode conversion. If an application using ICU processed crafted
data, content security mechanisms could be bypassed, potentially leading to
cross-site scripting (XSS) attacks.
Solution :
Upgrade to :
- icu-doc-3.8.1-3ubuntu1.1 (Ubuntu 9.04)
- lib32icu-dev-3.8.1-3ubuntu1.1 (Ubuntu 9.04)
- lib32icu38-3.8.1-3ubuntu1.1 (Ubuntu 9.04)
- libicu-dev-3.8.1-3ubuntu1.1 (Ubuntu 9.04)
- libicu38-3.8.1-3ubuntu1.1 (Ubuntu 9.04)
- libicu38-dbg-3.8.1-3ubuntu1.1 (Ubuntu 9.04)
Risk factor :
Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
only registered users with at least 25 hack challenge points can see links: click here in order to visit the hack challengesMore...