USN-2740-1 ICU Vulnerabilities
Medium to Low
- icu - International Components for Unicode library
Atte Kettunen discovered that ICU incorrectly handled certain converter names. If an application using ICU processed crafted data, a remote attacker could possibly cause it to crash. (CVE-2015-1270)
It was discovered that ICU incorrectly handled certain memory operations when processing data. If an application using ICU processed crafted data, a remote attacker could possibly cause it to crash or potentially execute arbitrary code with the privileges of the user invoking the program. (CVE-2015-2632, CVE-2015-4760)
Affected VMware Products and Versions
Severity is medium unless otherwise noted.
- BOSH: All versions of Cloud Foundry BOSH stemcells prior to v3094 are vulnerable to the aforementioned CVEs.
- Cloud Foundry Runtime: all versions of cf-release prior to 219 are vulnerable to the aforementioned CVEs.
- PHP Buildpack: all versions of the buildpack prior to 4.1.4 contain a vulnerable version of libicu52.
- Products in the PCF Suite which reference BOSH stemcell v3093 or earlier are vulnerable to the aforementioned CVE:
- Ops Manager v1.5.6 or earlier
- Elastic Runtime v1.5.5 or earlier
- MySQL for Pivotal Cloud Foundry v1.6.2 or earlier
- Session State Caching Powered by Pivotal GemFire v1.0.2 or earlier
- RabbitMQ for Pivotal Cloud Foundry v1.4.4 or earlier
- Redis for Pivotal Cloud Foundry v1.4.8 or earlier
Users of affected versions should apply the following mitigation:
- The Cloud Foundry project recommends that Cloud Foundry Deployments using BOSH stemcell v3093 or earlier upgrade to v3094 or later, which contain the patched versions of the Linux kernel to resolve the aforementioned CVEs.
- The Cloud Foundry project recommends that Cloud Foundry Deployments using cf-release 218 or lower upgrade to 219 or higher to resolve the aforementioned CVEs.
- Pivotal recommends customers upgrade to the following releases in the PCF Suite:
- Ops Manager 1.5.7 or higher
- Elastic Runtime 1.5.6 or higher
- PHP Buildpack 4.1.4 or higher
- Ops Metrics 1.4.4 or higher
- MySQL for PCF 1.6.3 or higher
- Session State Caching Powered by Pivotal GemFire 1.1.0 or higher
- Redis for PCF 1.4.8 or higher
- RabbitMQ for PCF 1.4.5 or higher