{"id":"MGASA-2013-0315","summary":"Updated icu packages fix multiple security vulnerbilities","details":"Updated icu packages fix security vulnerabilities:\n\nIt was discovered that ICU contained a race condition affecting multi-\nthreaded applications. If an application using ICU processed crafted data,\nan attacker could cause it to crash or potentially execute arbitrary code\nwith the privileges of the user invoking the program (CVE-2013-0900).\n\nIt was discovered that ICU incorrectly handled memory operations. If an\napplication using ICU processed crafted data, an attacker could cause it to\ncrash or potentially execute arbitrary code with the privileges of the user\ninvoking the program (CVE-2013-2924).\n","modified":"2026-04-16T06:22:50.441546233Z","published":"2013-10-25T20:57:48Z","upstream":["CVE-2013-0900","CVE-2013-2924"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2013-0315.html"},{"type":"WEB","url":"http://www.ubuntu.com/usn/usn-1989-1/"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=11362"}],"affected":[{"package":{"name":"icu","ecosystem":"Mageia:2","purl":"pkg:rpm/mageia/icu?arch=source&distro=mageia-2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.8.1.1-2.1.mga2"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2013-0315.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}