Red Hat Bugzilla – Bug 464168
CVE-2008-1036 ICU: Invalid character sequences omission during conversion of some character encodings (XSS attack possible)
Last modified: 2016-03-04 07:36:49 EST
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-1036 to
the following vulnerability:
International Components for Unicode (ICU) in Apple Mac OS X before 10.5.3 omits some invalid character sequences during conversion of some character encodings, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.
Proposed patch (icu part):
Proposed patch (icu4j part):
This issue affects the versions of the ICU package, as shipped with Red Hat
Enterprise Linux 5 (icu-3.6.5-11.1.el5), with Red Hat Directory Server 8.0 (icu-3.6-4.el4dsrv and icu-3.6.1 for DS8.0 sparc), with the Red Hat Enterprise MRG product version 1.0 (icu-3.6.5-12.el4), within the Extra Packages for Enterprise Linux (EPEL) project (icu-3.6.4.el4.20) and as shipped with the
Fedora releases of 8, 9 and 10.
This issue does NOT affect the versions of the icu4j package, as shipped
with Red Hat Application Stacks version 1 update 3 and version 2 update 1,
with JBOSS Enterprise Application Platform release 4.2.0 and 4.3.0 and
as shipped with Fedora releases of 8 and 9.
Created attachment 321139 [details]
Here's my backport of the patch for reference
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2009:0296 http://rhn.redhat.com/errata/RHSA-2009:0296.html
*** Bug 467974 has been marked as a duplicate of this bug. ***