CVE-2009-0153
published 2009-05-13CVE-2009-0153: International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as used in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, iPhone…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
3.68%
88.5th percentile
International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as used in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Fedora 9 and 10, and possibly other operating systems, does not properly handle invalid byte sequences during Unicode conversion, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| debian | icu | < icu 4.0.1-1 (bookworm) | icu 4.0.1-1 (bookworm) |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ICU vulnerability
vendor_ubuntu·2009-10-08
CVE-2009-0153 ICU vulnerability
Title: ICU vulnerability
Summary: ICU vulnerability
It was discovered that ICU did not properly handle invalid byte sequences
during Unicode conversion. If an application using ICU processed crafted
data, content security mechanisms could be bypassed, potentially leading to
cross-site scripting (XSS) attacks.
Instructions: After a standard system upgrade you need to restart applications linked
against libicu, such as OpenOffice.org, to effect the necessary changes.
Debian
CVE-2009-0153: icu - International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as ...
vendor_debian·2009·CVSS 4.3
CVE-2009-0153 [MEDIUM] CVE-2009-0153: icu - International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as ...
International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as used in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Fedora 9 and 10, and possibly other operating systems, does not properly handle invalid byte sequences during Unicode conversion, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.
Scope: local
bookworm: resolved (fixed in 4.0.1-1)
bullseye: resolved (fixed in 4.0.1-1)
forky: resolved (fixed in 4.0.1-1)
sid: resolved (fixed in 4.0.1-1)
trixie: resolved (fixed in 4.0.1-1)
Red Hat
icu: XSS vulnerability due to improper invalid byte sequence handling
vendor_redhat·2007-04-17·CVSS 4.3
CVE-2009-0153 [MEDIUM] CWE-79 icu: XSS vulnerability due to improper invalid byte sequence handling
icu: XSS vulnerability due to improper invalid byte sequence handling
International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as used in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Fedora 9 and 10, and possibly other operating systems, does not properly handle invalid byte sequences during Unicode conversion, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.
GHSA
GHSA-hc72-qh6j-jvwc: International Components for Unicode (ICU) 4
ghsa_unreviewed·2022-05-02
CVE-2009-0153 [MEDIUM] CWE-79 GHSA-hc72-qh6j-jvwc: International Components for Unicode (ICU) 4
International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as used in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Fedora 9 and 10, and possibly other operating systems, does not properly handle invalid byte sequences during Unicode conversion, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.
OSV
CVE-2009-0153: International Components for Unicode (ICU) 4
osv·2009-05-13·CVSS 4.3
CVE-2009-0153 [MEDIUM] CVE-2009-0153: International Components for Unicode (ICU) 4
International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as used in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Fedora 9 and 10, and possibly other operating systems, does not properly handle invalid byte sequences during Unicode conversion, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.
No detection rules found.
No public exploits indexed.
http://bugs.icu-project.org/trac/ticket/5691http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2009/jun/msg00002.htmlhttp://secunia.com/advisories/35074http://secunia.com/advisories/35379http://secunia.com/advisories/35436http://secunia.com/advisories/35498http://secunia.com/advisories/35584http://support.apple.com/kb/HT3549http://support.apple.com/kb/HT3613http://support.apple.com/kb/HT3639http://www.redhat.com/support/errata/RHSA-2009-1122.htmlhttp://www.securityfocus.com/bid/34926http://www.securityfocus.com/bid/34974http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/1297http://www.vupen.com/english/advisories/2009/1522http://www.vupen.com/english/advisories/2009/1621https://bugzilla.redhat.com/show_bug.cgi?id=503071https://exchange.xforce.ibmcloud.com/vulnerabilities/50488https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11366https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00336.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00478.htmlhttp://bugs.icu-project.org/trac/ticket/5691http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2009/jun/msg00002.htmlhttp://secunia.com/advisories/35074http://secunia.com/advisories/35379http://secunia.com/advisories/35436http://secunia.com/advisories/35498http://secunia.com/advisories/35584http://support.apple.com/kb/HT3549http://support.apple.com/kb/HT3613http://support.apple.com/kb/HT3639http://www.redhat.com/support/errata/RHSA-2009-1122.htmlhttp://www.securityfocus.com/bid/34926http://www.securityfocus.com/bid/34974http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/1297http://www.vupen.com/english/advisories/2009/1522http://www.vupen.com/english/advisories/2009/1621https://bugzilla.redhat.com/show_bug.cgi?id=503071https://exchange.xforce.ibmcloud.com/vulnerabilities/50488https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11366https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00336.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00478.html
2009-05-13
Published