Bug 1523136 (CVE-2017-15422)

Summary: CVE-2017-15422 chromium-browser: integer overflow in icu
Product: [Other] Security Response Reporter: Andrej Nemec <anemec>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: dmoppert, mfabian, tcallawa, tpopela, yaneti
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Fixed In Version: chromium-browser 63.0.3239.84 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-08 03:32:49 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On: 1523143, 1523144, 1523145, 1523146, 1526889, 1526890, 1526891, 1526892    
Bug Blocks: 1523164, 1524255    

Description Andrej Nemec 2017-12-07 09:54:26 UTC
An integer overflow flaw was found in the ICU component of the Chromium browser.

Upstream bug(s):


External References:


Comment 1 Andrej Nemec 2017-12-07 10:06:26 UTC
Created chromium tracking bugs for this issue:

Affects: epel-7 [bug 1523143]
Affects: fedora-all [bug 1523145]

Comment 3 errata-xmlrpc 2017-12-07 19:32:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6 Supplementary

Via RHSA-2017:3401 https://access.redhat.com/errata/RHSA-2017:3401

Comment 4 Huzaifa S. Sidhpurwala 2017-12-18 06:47:27 UTC
Created icu tracking bugs for this issue:

Affects: fedora-all [bug 1526891]

Created mingw-icu tracking bugs for this issue:

Affects: epel-7 [bug 1526889]

Comment 5 Huzaifa S. Sidhpurwala 2017-12-18 06:50:28 UTC
Created mingw-icu tracking bugs for this issue:

Affects: fedora-all [bug 1526892]