cbcvebase.
CVE-2014-7923
published 2015-01-22

CVE-2014-7923: The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91…

high7.5CVSS 3.0
AVNACLAuNCPIPAP
The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a look-behind expression.

Affected

13 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debianicu< icu 52.1-7.1 (bookworm)icu 52.1-7.1 (bookworm)
googlechrome<= 40.0.2214.85
icu-projectinternational_components_for_unicode< 55.155.1
opensuseopensuse
opensuseopensuse
oraclecommunications_messaging_server
oraclecommunications_messaging_server
redhatenterprise_linux_desktop_supplementary
redhatenterprise_linux_server_supplementary
redhatenterprise_linux_server_supplementary_eus
redhatenterprise_linux_workstation_supplementary

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd7.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv10.0CRITICAL