International Components for Unicode (ICU) for C/C++ has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_setNativeIndex* function. References: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=213 Upstream patch: http://bugs.icu-project.org/trac/changeset/39671
Created icu tracking bugs for this issue: Affects: fedora-all [bug 1444101] Created mingw-icu tracking bugs for this issue: Affects: epel-7 [bug 1444100] Affects: fedora-all [bug 1444099]
*** Bug 1444098 has been marked as a duplicate of this bug. ***
The OOB writes demonstrated by the oss-fuzz crasher are small writes in a libicu internal structure, with very little control (size, location or content) accessible to the attacker. The risk of ACE through this flaw is very small.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.