Common Vulnerabilities and Exposures assigned an identifier CVE-2008-1036 to the following vulnerability: International Components for Unicode (ICU) in Apple Mac OS X before 10.5.3 omits some invalid character sequences during conversion of some character encodings, which might allow remote attackers to conduct cross-site scripting (XSS) attacks. References: http://lists.apple.com/archives/security-announce/2008//May/msg00001.html Proposed patch (icu part): http://bugs.icu-project.org/trac/search?q=%22ticket:6175:%22&noquickjump=1&changeset=on Proposed patch (icu4j part): http://bugs.icu-project.org/trac/search?q=%22ticket:6198:%22&noquickjump=1&changeset=on
This issue affects the versions of the ICU package, as shipped with Red Hat Enterprise Linux 5 (icu-3.6.5-11.1.el5), with Red Hat Directory Server 8.0 (icu-3.6-4.el4dsrv and icu-3.6.1 for DS8.0 sparc), with the Red Hat Enterprise MRG product version 1.0 (icu-3.6.5-12.el4), within the Extra Packages for Enterprise Linux (EPEL) project (icu-3.6.4.el4.20) and as shipped with the Fedora releases of 8, 9 and 10.
This issue does NOT affect the versions of the icu4j package, as shipped with Red Hat Application Stacks version 1 update 3 and version 2 update 1, with JBOSS Enterprise Application Platform release 4.2.0 and 4.3.0 and as shipped with Fedora releases of 8 and 9.
Created attachment 321139 [details] Here's my backport of the patch for reference
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2009:0296 http://rhn.redhat.com/errata/RHSA-2009:0296.html
*** Bug 467974 has been marked as a duplicate of this bug. ***