ID

VAR-200902-0880


CVE

CVE-2009-0153


TITLE

Apple Mac OS X of ICU Vulnerable to cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2009-001326

DESCRIPTION

International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as used in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Fedora 9 and 10, and possibly other operating systems, does not properly handle invalid byte sequences during Unicode conversion, which might allow remote attackers to conduct cross-site scripting (XSS) attacks. The International Components for Unicode is prone to an input-validation vulnerability because the library may incorrectly convert some invalid byte sequences. An attacker may leverage this vulnerability to bypass content filters. This may lead to cross-site scripting attacks or allow the attacker to obtain sensitive information in some cases. Other attacks are also possible. NOTE: This issue was previously covered in BID 34926 (Apple Mac OS X 2009-002 Multiple Security Vulnerabilities), but has been assigned its own record to better document it. Mac OS X is the operating system used by the Apple family of machines. There is a bug in the implementation of ICU's handling of certain character encodings. =========================================================== Ubuntu Security Notice USN-846-1 October 08, 2009 icu vulnerability CVE-2009-0153 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: libicu38 3.8-6ubuntu0.2 Ubuntu 8.10: libicu38 3.8.1-2ubuntu0.2 Ubuntu 9.04: libicu38 3.8.1-3ubuntu1.1 After a standard system upgrade you need to restart applications linked against libicu, such as OpenOffice.org, to effect the necessary changes. If an application using ICU processed crafted data, content security mechanisms could be bypassed, potentially leading to cross-site scripting (XSS) attacks. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA-1889-1 security@debian.org http://www.debian.org/security/ Moritz Muehlenhoff September 16, 2009 http://www.debian.org/security/faq - ------------------------------------------------------------------------ Package : icu Vulnerability : programming error Problem type : local(remote) Debian-specific: no CVE Id(s) : CVE-2009-0153 It was discovered that the ICU unicode library performed incorrect processing of invalid multibyte sequences, resulting in potential bypass of security mechanisms. For the old stable distribution (etch), this problem has been fixed in version 3.6-2etch3. For the stable distribution (lenny), this problem has been fixed in version 3.8.1-3+lenny2. For the unstable distribution (sid), this problem has been fixed in version 4.0.1-1. We recommend that you upgrade your icu packages. Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0 alias etch - ------------------------------- Oldstable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: http://security.debian.org/pool/updates/main/i/icu/icu_3.6-2etch3.dsc Size/MD5 checksum: 592 8b600075600533ce08c9801ffa571a19 http://security.debian.org/pool/updates/main/i/icu/icu_3.6-2etch3.diff.gz Size/MD5 checksum: 45190 601af38fe10a27e08e40985c409bc6c4 http://security.debian.org/pool/updates/main/i/icu/icu_3.6.orig.tar.gz Size/MD5 checksum: 9778863 0f1bda1992b4adca62da68a7ad79d830 Architecture independent packages: http://security.debian.org/pool/updates/main/i/icu/icu-doc_3.6-2etch3_all.deb Size/MD5 checksum: 3239572 8bf16fb7db375fb14de7082bcb814733 alpha architecture (DEC Alpha) http://security.debian.org/pool/updates/main/i/icu/libicu36_3.6-2etch3_alpha.deb Size/MD5 checksum: 5586140 1244a1b89188c020a97468dc25d22af7 http://security.debian.org/pool/updates/main/i/icu/libicu36-dev_3.6-2etch3_alpha.deb Size/MD5 checksum: 7012868 8680617bb8c38f6abef169b572a76baa amd64 architecture (AMD x86_64 (AMD64)) http://security.debian.org/pool/updates/main/i/icu/libicu36_3.6-2etch3_amd64.deb Size/MD5 checksum: 5444866 f9271ec21977880f74955cfe06b7580d http://security.debian.org/pool/updates/main/i/icu/libicu36-dev_3.6-2etch3_amd64.deb Size/MD5 checksum: 6573726 25374ce8e6ae12b655a9744db65b9455 hppa architecture (HP PA RISC) http://security.debian.org/pool/updates/main/i/icu/libicu36_3.6-2etch3_hppa.deb Size/MD5 checksum: 5913798 20c8976b23d28d9bc91ea053748d79e0 http://security.debian.org/pool/updates/main/i/icu/libicu36-dev_3.6-2etch3_hppa.deb Size/MD5 checksum: 7110674 bee82145df32672bf5d61e29dd3d6bc3 i386 architecture (Intel ia32) http://security.debian.org/pool/updates/main/i/icu/libicu36-dev_3.6-2etch3_i386.deb Size/MD5 checksum: 6466444 d8e1c31e6f1d238353340a9b82da1ed8 http://security.debian.org/pool/updates/main/i/icu/libicu36_3.6-2etch3_i386.deb Size/MD5 checksum: 5470148 f5d9e50ecb224df9ae4f0c7057097f54 ia64 architecture (Intel ia64) http://security.debian.org/pool/updates/main/i/icu/libicu36_3.6-2etch3_ia64.deb Size/MD5 checksum: 5869036 c305e7cff86ad5584c4842fec7619fd8 http://security.debian.org/pool/updates/main/i/icu/libicu36-dev_3.6-2etch3_ia64.deb Size/MD5 checksum: 7243932 effc8dc2ed962de903e848ff402c167a mips architecture (MIPS (Big Endian)) http://security.debian.org/pool/updates/main/i/icu/libicu36_3.6-2etch3_mips.deb Size/MD5 checksum: 5747354 39624db186bbf7ce259c47681d0a1cfc http://security.debian.org/pool/updates/main/i/icu/libicu36-dev_3.6-2etch3_mips.deb Size/MD5 checksum: 7052540 c159699731d592ec60fcfd4bbe010a51 mipsel architecture (MIPS (Little Endian)) http://security.debian.org/pool/updates/main/i/icu/libicu36-dev_3.6-2etch3_mipsel.deb Size/MD5 checksum: 6769230 32e24d0b40b3f2e62e0c2c4c4be96dce http://security.debian.org/pool/updates/main/i/icu/libicu36_3.6-2etch3_mipsel.deb Size/MD5 checksum: 5464426 5f544b29dd41d8326ddfd70b31e4045a powerpc architecture (PowerPC) http://security.debian.org/pool/updates/main/i/icu/libicu36-dev_3.6-2etch3_powerpc.deb Size/MD5 checksum: 6891510 af8e8b416b43a9d6c5f5893dd63261d6 http://security.debian.org/pool/updates/main/i/icu/libicu36_3.6-2etch3_powerpc.deb Size/MD5 checksum: 5750422 ec7b53398b703da8f7e166a33768e260 s390 architecture (IBM S/390) http://security.debian.org/pool/updates/main/i/icu/libicu36-dev_3.6-2etch3_s390.deb Size/MD5 checksum: 6896648 d6e3cde239924756df46b084e80388d4 http://security.debian.org/pool/updates/main/i/icu/libicu36_3.6-2etch3_s390.deb Size/MD5 checksum: 5781028 e5c3b53fdcda2562a206d92b15a5f520 sparc architecture (Sun SPARC/UltraSPARC) http://security.debian.org/pool/updates/main/i/icu/libicu36-dev_3.6-2etch3_sparc.deb Size/MD5 checksum: 6774462 94ce55cf609a906af5336f32b6c2ee22 http://security.debian.org/pool/updates/main/i/icu/libicu36_3.6-2etch3_sparc.deb Size/MD5 checksum: 5673738 d63d35c169da448d83074fa45e25ed64 Debian GNU/Linux 5.0 alias lenny - -------------------------------- Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: http://security.debian.org/pool/updates/main/i/icu/icu_3.8.1-3+lenny2.diff.gz Size/MD5 checksum: 41943 57d76fe9884c543a634bfd44425a42c6 http://security.debian.org/pool/updates/main/i/icu/icu_3.8.1.orig.tar.gz Size/MD5 checksum: 10591204 ca52a1eb5050478f5f7d24e16ce01f57 http://security.debian.org/pool/updates/main/i/icu/icu_3.8.1-3+lenny2.dsc Size/MD5 checksum: 1298 e0528ce00964025af9b2f940f588664a Architecture independent packages: http://security.debian.org/pool/updates/main/i/icu/icu-doc_3.8.1-3+lenny2_all.deb Size/MD5 checksum: 3659700 69882d02e07863b195b7e9b798bdeff2 alpha architecture (DEC Alpha) http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_alpha.deb Size/MD5 checksum: 6068242 7e4d26e612e178ebac27cbd2a7db72a9 http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_alpha.deb Size/MD5 checksum: 7568600 18c17c486d3ee39d0c0b1574d219c228 http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_alpha.deb Size/MD5 checksum: 2366836 bb1325175eb3086459d6a1daba52d010 amd64 architecture (AMD x86_64 (AMD64)) http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_amd64.deb Size/MD5 checksum: 5932454 22e0013e161bf6ec46fdb7e330fa9c2e http://security.debian.org/pool/updates/main/i/icu/lib32icu38_3.8.1-3+lenny2_amd64.deb Size/MD5 checksum: 5919044 c785a70caa0bf88a644f0b65011915ee http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_amd64.deb Size/MD5 checksum: 2404096 2ce67914c39c474ff42f57ffc24bb263 http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_amd64.deb Size/MD5 checksum: 7123322 5357c9591d7cea42b4cd9bd00b6c9114 http://security.debian.org/pool/updates/main/i/icu/lib32icu-dev_3.8.1-3+lenny2_amd64.deb Size/MD5 checksum: 6063026 bde21ee163171d88d1d3b96cfa795d9b arm architecture (ARM) http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_arm.deb Size/MD5 checksum: 5910002 195d7e79719dc7b6275776eb29b28b3a http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_arm.deb Size/MD5 checksum: 7183106 d5939d433c5e647e1c75af8fb27351d7 http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_arm.deb Size/MD5 checksum: 2287448 c3e04dae0ad884951cc1ba6663026fed armel architecture (ARM EABI) http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_armel.deb Size/MD5 checksum: 5848632 1adf442fa32cd182384d2d2608000ef8 http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_armel.deb Size/MD5 checksum: 7420504 f593ee94d7bdb4bb8c0796aebfaccd61 http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_armel.deb Size/MD5 checksum: 1758708 cffc60f24a4293d362d82fb6483d38fd hppa architecture (HP PA RISC) http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_hppa.deb Size/MD5 checksum: 6379014 1cdb8e9a77f953d7846eb12976efb04f http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_hppa.deb Size/MD5 checksum: 7667266 2b4fa947ccb1c56e0a1ab997081349ad http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_hppa.deb Size/MD5 checksum: 2360524 012847a53a622bb3dff6a522c0521801 i386 architecture (Intel ia32) http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_i386.deb Size/MD5 checksum: 2278340 b95d691813f7d32d7bc1a8aa96ddcd94 http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_i386.deb Size/MD5 checksum: 6975168 e5c844c5ce908655075dd49c57182b3f http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_i386.deb Size/MD5 checksum: 5918780 a471bd785fecadc4a7acd91be38a1bca ia64 architecture (Intel ia64) http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_ia64.deb Size/MD5 checksum: 6398722 9a8fb2a23112dfa081285f2b34bc2c48 http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_ia64.deb Size/MD5 checksum: 7828890 a56ec00c1e33f8abaaa73e211e3f26c1 http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_ia64.deb Size/MD5 checksum: 2210326 674686adc1b87ef59144e90fdddb6e8a mips architecture (MIPS (Big Endian)) http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_mips.deb Size/MD5 checksum: 6209236 3f2f1f954799ec7c20226b66578496fb http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_mips.deb Size/MD5 checksum: 7601662 e5873a370ba2f10e07ba438221ec9326 http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_mips.deb Size/MD5 checksum: 2475268 9ccfeff2fbd457798ad595513c3fceb8 mipsel architecture (MIPS (Little Endian)) http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_mipsel.deb Size/MD5 checksum: 7294770 e7a2b87be42cf6c2eb5defc1f16fcd1b http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_mipsel.deb Size/MD5 checksum: 5900392 1fd37ee3d1d15c3ad251a5b4e2707275 http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_mipsel.deb Size/MD5 checksum: 2408066 8c5b8b9e7eb46d8404d6fbdf319ba647 powerpc architecture (PowerPC) http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_powerpc.deb Size/MD5 checksum: 2378760 842531d765b7bcd25f27535f7e2195fa http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_powerpc.deb Size/MD5 checksum: 7462340 0ce58e5b42bf6cea3488fc55af9b0721 http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_powerpc.deb Size/MD5 checksum: 6292462 d8ca2eb3b172e43405339d1ddb233b66 s390 architecture (IBM S/390) http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_s390.deb Size/MD5 checksum: 7436198 33277bb42e73a64ae8421c5ce4cc390a http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_s390.deb Size/MD5 checksum: 6270994 b23dd748a28ccde33d87d7df945693a2 http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_s390.deb Size/MD5 checksum: 2471744 926e06bca83a31ce3aca813409cc95a8 sparc architecture (Sun SPARC/UltraSPARC) http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_sparc.deb Size/MD5 checksum: 7304054 9f98cb39fce383087d192faa2fc47386 http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_sparc.deb Size/MD5 checksum: 2135440 3db054d567561c48e935814465e4a525 http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_sparc.deb Size/MD5 checksum: 6146402 1bfc509accd39f0ca52b871b4af534a2 These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb http://security.debian.org/ stable/updates main For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main Mailing list: debian-security-announce@lists.debian.org Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAkqxN9cACgkQXm3vHE4uylp6WACcDP/faUO12bVfOeG8qVHMiiRv oKUAn0ZXj9WAkxDxgUbpM2SEG6TuoUgo =FNYT -----END PGP SIGNATURE-----

Trust: 2.16

sources: NVD: CVE-2009-0153 // JVNDB: JVNDB-2009-001326 // BID: 34974 // VULHUB: VHN-37599 // PACKETSTORM: 81881 // PACKETSTORM: 81386

AFFECTED PRODUCTS

vendor:applemodel:mac os xscope:eqversion:10.5.4

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.5.5

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.5.2

Trust: 1.6

vendor:applemodel:mac os x serverscope:eqversion:10.5.6

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.5.1

Trust: 1.6

vendor:applemodel:mac os x serverscope:eqversion:10.5.2

Trust: 1.6

vendor:applemodel:mac os x serverscope:eqversion:10.5.1

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.5.3

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.5.6

Trust: 1.6

vendor:applemodel:mac os x serverscope:eqversion:10.5.3

Trust: 1.6

vendor:applemodel:mac os x serverscope:eqversion:10.5.5

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.5.4

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.5.0

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.5.0

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:v10.5 to v10.5.6

Trust: 0.8

vendor:applemodel:mac os x serverscope:eqversion:v10.5 to v10.5.6

Trust: 0.8

vendor:applemodel:iosscope:eqversion:1.0 to 2.2.1

Trust: 0.8

vendor:applemodel:ios for ipod touchscope:eqversion:1.1 to 2.2.1

Trust: 0.8

vendor:applemodel:safariscope:ltversion:4.0

Trust: 0.8

vendor:cybertrustmodel:asianux serverscope:eqversion:3 (x86)

Trust: 0.8

vendor:cybertrustmodel:asianux serverscope:eqversion:3 (x86-64)

Trust: 0.8

vendor:red hatmodel:enterprise linuxscope:eqversion:5 (server)

Trust: 0.8

vendor:red hatmodel:enterprise linux desktopscope:eqversion:5.0 (client)

Trust: 0.8

vendor:red hatmodel:enterprise linux eusscope:eqversion:5.3.z (server)

Trust: 0.8

vendor:red hatmodel:rhel desktop workstationscope:eqversion:5 (client)

Trust: 0.8

vendor:ubuntumodel:linux sparcscope:eqversion:9.04

Trust: 0.3

vendor:ubuntumodel:linux powerpcscope:eqversion:9.04

Trust: 0.3

vendor:ubuntumodel:linux lpiascope:eqversion:9.04

Trust: 0.3

vendor:ubuntumodel:linux i386scope:eqversion:9.04

Trust: 0.3

vendor:ubuntumodel:linux amd64scope:eqversion:9.04

Trust: 0.3

vendor:ubuntumodel:linux sparcscope:eqversion:8.10

Trust: 0.3

vendor:ubuntumodel:linux powerpcscope:eqversion:8.10

Trust: 0.3

vendor:ubuntumodel:linux lpiascope:eqversion:8.10

Trust: 0.3

vendor:ubuntumodel:linux i386scope:eqversion:8.10

Trust: 0.3

vendor:ubuntumodel:linux amd64scope:eqversion:8.10

Trust: 0.3

vendor:ubuntumodel:linux lts sparcscope:eqversion:8.04

Trust: 0.3

vendor:ubuntumodel:linux lts powerpcscope:eqversion:8.04

Trust: 0.3

vendor:ubuntumodel:linux lts lpiascope:eqversion:8.04

Trust: 0.3

vendor:ubuntumodel:linux lts i386scope:eqversion:8.04

Trust: 0.3

vendor:ubuntumodel:linux lts amd64scope:eqversion:8.04

Trust: 0.3

vendor:susemodel:linux enterprise serverscope:eqversion:9

Trust: 0.3

vendor:susemodel:linux enterprisescope:eqversion:11

Trust: 0.3

vendor:susemodel:linux enterprisescope:eqversion:10

Trust: 0.3

vendor:s u s emodel:opensusescope:eqversion:11.1

Trust: 0.3

vendor:s u s emodel:opensusescope:eqversion:11.0

Trust: 0.3

vendor:s u s emodel:opensusescope:eqversion:10.3

Trust: 0.3

vendor:redhatmodel:enterprise linux desktop workstation clientscope:eqversion:5

Trust: 0.3

vendor:redhatmodel:enterprise linux desktop clientscope:eqversion:5

Trust: 0.3

vendor:redhatmodel:enterprise linux serverscope:eqversion:5

Trust: 0.3

vendor:debianmodel:linux sparcscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux s/390scope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux powerpcscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux mipselscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux mipsscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux m68kscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux ia-64scope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux ia-32scope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux hppascope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux armelscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux armscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux amd64scope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux alphascope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linuxscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux sparcscope:eqversion:4.0

Trust: 0.3

vendor:debianmodel:linux s/390scope:eqversion:4.0

Trust: 0.3

vendor:debianmodel:linux powerpcscope:eqversion:4.0

Trust: 0.3

vendor:debianmodel:linux mipselscope:eqversion:4.0

Trust: 0.3

vendor:debianmodel:linux mipsscope:eqversion:4.0

Trust: 0.3

vendor:debianmodel:linux m68kscope:eqversion:4.0

Trust: 0.3

vendor:debianmodel:linux ia-64scope:eqversion:4.0

Trust: 0.3

vendor:debianmodel:linux ia-32scope:eqversion:4.0

Trust: 0.3

vendor:debianmodel:linux hppascope:eqversion:4.0

Trust: 0.3

vendor:debianmodel:linux armelscope:eqversion:4.0

Trust: 0.3

vendor:debianmodel:linux armscope:eqversion:4.0

Trust: 0.3

vendor:debianmodel:linux amd64scope:eqversion:4.0

Trust: 0.3

vendor:debianmodel:linux alphascope:eqversion:4.0

Trust: 0.3

vendor:debianmodel:linuxscope:eqversion:4.0

Trust: 0.3

vendor:avayamodel:aura session managerscope:eqversion:1.1

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.6

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.5

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.4

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.3

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.2

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.1

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.6

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.5

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.4

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.3

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5

Trust: 0.3

vendor:applemodel:ipod touchscope:eqversion:2.2.1

Trust: 0.3

vendor:applemodel:ipod touchscope:eqversion:2.0.2

Trust: 0.3

vendor:applemodel:ipod touchscope:eqversion:2.0.1

Trust: 0.3

vendor:applemodel:ipod touchscope:eqversion:1.1.4

Trust: 0.3

vendor:applemodel:ipod touchscope:eqversion:1.1.3

Trust: 0.3

vendor:applemodel:ipod touchscope:eqversion:1.1.2

Trust: 0.3

vendor:applemodel:ipod touchscope:eqversion:1.1.1

Trust: 0.3

vendor:applemodel:ipod touchscope:eqversion:2.2

Trust: 0.3

vendor:applemodel:ipod touchscope:eqversion:2.1

Trust: 0.3

vendor:applemodel:ipod touchscope:eqversion:2.0

Trust: 0.3

vendor:applemodel:ipod touchscope:eqversion:1.1

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:2.2.1

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:2.0.2

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:2.0.1

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:1.1.4

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:1.1.3

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:1.1.2

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:1.1.1

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:1.0.2

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:1.0.1

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:2.2

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:2.1

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:2.0

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:1.1

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:1

Trust: 0.3

vendor:applemodel:mac os serverscope:neversion:x10.5.7

Trust: 0.3

vendor:applemodel:mac osscope:neversion:x10.5.7

Trust: 0.3

vendor:applemodel:ipod touchscope:neversion:3.0

Trust: 0.3

vendor:applemodel:iphonescope:neversion:3.0

Trust: 0.3

sources: BID: 34974 // JVNDB: JVNDB-2009-001326 // CNNVD: CNNVD-200905-169 // NVD: CVE-2009-0153

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2009-0153
value: MEDIUM

Trust: 1.0

NVD: CVE-2009-0153
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-200905-169
value: MEDIUM

Trust: 0.6

VULHUB: VHN-37599
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2009-0153
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-37599
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-37599 // JVNDB: JVNDB-2009-001326 // CNNVD: CNNVD-200905-169 // NVD: CVE-2009-0153

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-37599 // JVNDB: JVNDB-2009-001326 // NVD: CVE-2009-0153

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200905-169

TYPE

xss

Trust: 0.7

sources: PACKETSTORM: 81881 // CNNVD: CNNVD-200905-169

CONFIGURATIONS

sources: JVNDB: JVNDB-2009-001326

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-37599

PATCH

title:HT3613url:http://support.apple.com/kb/HT3613

Trust: 0.8

title:HT3639url:http://support.apple.com/kb/HT3639

Trust: 0.8

title:HT3549url:http://support.apple.com/kb/HT3549

Trust: 0.8

title:HT3613url:http://support.apple.com/kb/HT3613?viewlocale=ja_JP

Trust: 0.8

title:HT3639url:http://support.apple.com/kb/HT3639?viewlocale=ja_JP

Trust: 0.8

title:HT3549url:http://support.apple.com/kb/HT3549?viewlocale=ja_JP

Trust: 0.8

title:icu-3.6-5.11.4url:https://tsn.miraclelinux.com/tsn_local/index.php?m=errata&a=detail&eid=449

Trust: 0.8

title:RHSA-2009:1122url:https://rhn.redhat.com/errata/RHSA-2009-1122.html

Trust: 0.8

title:RHSA-2009:1122url:https://www.jp.redhat.com/support/errata/RHSA/RHSA-2009-1122J.html

Trust: 0.8

title:TA09-133Aurl:http://software.fujitsu.com/jp/security/vulnerabilities/ta09-133a.html

Trust: 0.8

sources: JVNDB: JVNDB-2009-001326

EXTERNAL IDS

db:NVDid:CVE-2009-0153

Trust: 3.0

db:VUPENid:ADV-2009-1522

Trust: 2.5

db:VUPENid:ADV-2009-1297

Trust: 2.5

db:USCERTid:TA09-133A

Trust: 2.5

db:SECUNIAid:35074

Trust: 2.5

db:BIDid:34974

Trust: 2.0

db:VUPENid:ADV-2009-1621

Trust: 1.7

db:SECUNIAid:35436

Trust: 1.7

db:SECUNIAid:35379

Trust: 1.7

db:SECUNIAid:35584

Trust: 1.7

db:SECUNIAid:35498

Trust: 1.7

db:BIDid:34926

Trust: 1.7

db:XFid:50488

Trust: 1.4

db:USCERTid:SA09-133A

Trust: 0.8

db:JVNDBid:JVNDB-2009-001326

Trust: 0.8

db:CNNVDid:CNNVD-200905-169

Trust: 0.7

db:APPLEid:APPLE-SA-2009-05-12

Trust: 0.6

db:APPLEid:APPLE-SA-2009-06-17-1

Trust: 0.6

db:APPLEid:APPLE-SA-2009-06-08-1

Trust: 0.6

db:REDHATid:RHSA-2009:1122

Trust: 0.6

db:FEDORAid:FEDORA-2009-6121

Trust: 0.6

db:FEDORAid:FEDORA-2009-6273

Trust: 0.6

db:CERT/CCid:TA09-133A

Trust: 0.6

db:PACKETSTORMid:81881

Trust: 0.2

db:PACKETSTORMid:81386

Trust: 0.2

db:VULHUBid:VHN-37599

Trust: 0.1

sources: VULHUB: VHN-37599 // BID: 34974 // JVNDB: JVNDB-2009-001326 // PACKETSTORM: 81881 // PACKETSTORM: 81386 // CNNVD: CNNVD-200905-169 // NVD: CVE-2009-0153

REFERENCES

url:http://www.us-cert.gov/cas/techalerts/ta09-133a.html

Trust: 2.5

url:http://secunia.com/advisories/35074

Trust: 2.5

url:http://www.vupen.com/english/advisories/2009/1297

Trust: 2.5

url:http://www.vupen.com/english/advisories/2009/1522

Trust: 2.5

url:http://lists.apple.com/archives/security-announce/2009/may/msg00002.html

Trust: 1.7

url:http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html

Trust: 1.7

url:http://lists.apple.com/archives/security-announce/2009/jun/msg00005.html

Trust: 1.7

url:http://www.securityfocus.com/bid/34926

Trust: 1.7

url:http://www.securityfocus.com/bid/34974

Trust: 1.7

url:http://bugs.icu-project.org/trac/ticket/5691

Trust: 1.7

url:http://support.apple.com/kb/ht3549

Trust: 1.7

url:http://support.apple.com/kb/ht3613

Trust: 1.7

url:http://support.apple.com/kb/ht3639

Trust: 1.7

url:https://bugzilla.redhat.com/show_bug.cgi?id=503071

Trust: 1.7

url:https://www.redhat.com/archives/fedora-package-announce/2009-june/msg00336.html

Trust: 1.7

url:https://www.redhat.com/archives/fedora-package-announce/2009-june/msg00478.html

Trust: 1.7

url:http://www.redhat.com/support/errata/rhsa-2009-1122.html

Trust: 1.7

url:http://secunia.com/advisories/35379

Trust: 1.7

url:http://secunia.com/advisories/35436

Trust: 1.7

url:http://secunia.com/advisories/35498

Trust: 1.7

url:http://secunia.com/advisories/35584

Trust: 1.7

url:http://www.vupen.com/english/advisories/2009/1621

Trust: 1.7

url:http://xforce.iss.net/xforce/xfdb/50488

Trust: 1.4

url:https://oval.cisecurity.org/repository/search/definition/oval%3aorg.mitre.oval%3adef%3a11366

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/50488

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2009-0153

Trust: 0.8

url:http://jvn.jp/cert/jvnta09-133a/

Trust: 0.8

url:http://jvn.jp/tr/jvntr-2009-12

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2009-0153

Trust: 0.8

url:http://www.us-cert.gov/cas/alerts/sa09-133a.html

Trust: 0.8

url:http://www.apple.com/macosx/

Trust: 0.3

url:http://support.avaya.com/elmodocs2/security/asa-2009-254.htm

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2009-0153

Trust: 0.2

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/libicu38_3.8-6ubuntu0.2_i386.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/libicu38-dbg_3.8.1-2ubuntu0.2_amd64.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu38-dbg_3.8-6ubuntu0.2_lpia.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/icu-doc_3.8-6ubuntu0.2_all.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/libicu-dev_3.8-6ubuntu0.2_i386.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu38-dbg_3.8-6ubuntu0.2_powerpc.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/libicu38-dbg_3.8-6ubuntu0.2_amd64.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu-dev_3.8-6ubuntu0.2_lpia.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/lib32icu38_3.8.1-3ubuntu1.1_amd64.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/lib32icu38_3.8-6ubuntu0.2_amd64.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu-dev_3.8.1-2ubuntu0.2_powerpc.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu-dev_3.8.1-3ubuntu1.1_sparc.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/icu_3.8.orig.tar.gz

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/lib32icu38_3.8.1-2ubuntu0.2_amd64.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/libicu38_3.8.1-2ubuntu0.2_amd64.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu38-dbg_3.8.1-2ubuntu0.2_sparc.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu-dev_3.8-6ubuntu0.2_powerpc.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/libicu38_3.8-6ubuntu0.2_amd64.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu38-dbg_3.8.1-2ubuntu0.2_lpia.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu38_3.8.1-3ubuntu1.1_powerpc.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu38_3.8-6ubuntu0.2_sparc.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/icu_3.8.1.orig.tar.gz

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/lib32icu-dev_3.8-6ubuntu0.2_amd64.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu-dev_3.8.1-2ubuntu0.2_lpia.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu38-dbg_3.8.1-3ubuntu1.1_powerpc.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/libicu38-dbg_3.8.1-2ubuntu0.2_i386.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu38_3.8.1-2ubuntu0.2_powerpc.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/lib32icu-dev_3.8.1-2ubuntu0.2_amd64.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/libicu-dev_3.8.1-3ubuntu1.1_amd64.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/libicu38-dbg_3.8.1-3ubuntu1.1_i386.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu38_3.8.1-3ubuntu1.1_lpia.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu38_3.8.1-3ubuntu1.1_sparc.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu38-dbg_3.8.1-3ubuntu1.1_sparc.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu-dev_3.8-6ubuntu0.2_sparc.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/libicu-dev_3.8-6ubuntu0.2_amd64.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/icu_3.8.1-2ubuntu0.2.dsc

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/lib32icu-dev_3.8.1-3ubuntu1.1_amd64.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu38-dbg_3.8.1-3ubuntu1.1_lpia.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu-dev_3.8.1-2ubuntu0.2_sparc.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/icu_3.8.1-2ubuntu0.2.diff.gz

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/icu_3.8-6ubuntu0.2.dsc

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu-dev_3.8.1-3ubuntu1.1_lpia.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/libicu38-dbg_3.8-6ubuntu0.2_i386.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/icu_3.8-6ubuntu0.2.diff.gz

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/icu_3.8.1-3ubuntu1.1.dsc

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/icu-doc_3.8.1-3ubuntu1.1_all.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/libicu-dev_3.8.1-3ubuntu1.1_i386.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/libicu38_3.8.1-3ubuntu1.1_amd64.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/libicu38_3.8.1-3ubuntu1.1_i386.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu38_3.8.1-2ubuntu0.2_sparc.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu38_3.8.1-2ubuntu0.2_lpia.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu-dev_3.8.1-3ubuntu1.1_powerpc.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu38-dbg_3.8.1-2ubuntu0.2_powerpc.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/libicu-dev_3.8.1-2ubuntu0.2_amd64.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu38_3.8-6ubuntu0.2_powerpc.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu38_3.8-6ubuntu0.2_lpia.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/libicu38-dbg_3.8.1-3ubuntu1.1_amd64.deb

Trust: 0.1

url:http://ports.ubuntu.com/pool/main/i/icu/libicu38-dbg_3.8-6ubuntu0.2_sparc.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/libicu-dev_3.8.1-2ubuntu0.2_i386.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/icu-doc_3.8.1-2ubuntu0.2_all.deb

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/icu_3.8.1-3ubuntu1.1.diff.gz

Trust: 0.1

url:http://security.ubuntu.com/ubuntu/pool/main/i/icu/libicu38_3.8.1-2ubuntu0.2_i386.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_sparc.deb

Trust: 0.1

url:http://packages.debian.org/<pkg>

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_arm.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/icu-doc_3.8.1-3+lenny2_all.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/icu_3.6.orig.tar.gz

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_s390.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_sparc.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu36_3.6-2etch3_alpha.deb

Trust: 0.1

url:http://www.debian.org/security/faq

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_armel.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu36-dev_3.6-2etch3_hppa.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu36-dev_3.6-2etch3_i386.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu36-dev_3.6-2etch3_ia64.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/lib32icu38_3.8.1-3+lenny2_amd64.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu36-dev_3.6-2etch3_mips.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu36_3.6-2etch3_sparc.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_hppa.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_arm.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu36_3.6-2etch3_mipsel.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu36-dev_3.6-2etch3_amd64.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu36_3.6-2etch3_powerpc.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu36_3.6-2etch3_amd64.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu36_3.6-2etch3_hppa.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/icu_3.8.1.orig.tar.gz

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_amd64.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu36-dev_3.6-2etch3_powerpc.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_armel.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_mips.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_sparc.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_mipsel.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_i386.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_s390.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu36-dev_3.6-2etch3_s390.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_hppa.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_mips.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_powerpc.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu36_3.6-2etch3_s390.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu36_3.6-2etch3_mips.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/icu_3.8.1-3+lenny2.diff.gz

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_armel.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_mipsel.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_ia64.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_amd64.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu36-dev_3.6-2etch3_alpha.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_alpha.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_i386.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_mips.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_mipsel.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu36_3.6-2etch3_i386.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/icu_3.6-2etch3.dsc

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/lib32icu-dev_3.8.1-3+lenny2_amd64.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/icu_3.6-2etch3.diff.gz

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_amd64.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu36-dev_3.6-2etch3_sparc.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu36_3.6-2etch3_ia64.deb

Trust: 0.1

url:http://security.debian.org/

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu36-dev_3.6-2etch3_mipsel.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_alpha.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_powerpc.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_ia64.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/icu-doc_3.6-2etch3_all.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_i386.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_arm.deb

Trust: 0.1

url:http://www.debian.org/security/

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_hppa.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38-dbg_3.8.1-3+lenny2_ia64.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu-dev_3.8.1-3+lenny2_powerpc.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_s390.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/libicu38_3.8.1-3+lenny2_alpha.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/i/icu/icu_3.8.1-3+lenny2.dsc

Trust: 0.1

sources: VULHUB: VHN-37599 // BID: 34974 // JVNDB: JVNDB-2009-001326 // PACKETSTORM: 81881 // PACKETSTORM: 81386 // CNNVD: CNNVD-200905-169 // NVD: CVE-2009-0153

CREDITS

Charlie MillerAndrew MortensenMoritz Jodeit moritz@jodeit.org

Trust: 0.6

sources: CNNVD: CNNVD-200905-169

SOURCES

db:VULHUBid:VHN-37599
db:BIDid:34974
db:JVNDBid:JVNDB-2009-001326
db:PACKETSTORMid:81881
db:PACKETSTORMid:81386
db:CNNVDid:CNNVD-200905-169
db:NVDid:CVE-2009-0153

LAST UPDATE DATE

2024-11-23T19:56:41.445000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-37599date:2017-09-29T00:00:00
db:BIDid:34974date:2015-04-13T21:50:00
db:JVNDBid:JVNDB-2009-001326date:2009-08-11T00:00:00
db:CNNVDid:CNNVD-200905-169date:2009-06-23T00:00:00
db:NVDid:CVE-2009-0153date:2024-11-21T00:59:11.767

SOURCES RELEASE DATE

db:VULHUBid:VHN-37599date:2009-05-13T00:00:00
db:BIDid:34974date:2009-05-12T00:00:00
db:JVNDBid:JVNDB-2009-001326date:2009-06-26T00:00:00
db:PACKETSTORMid:81881date:2009-10-09T00:22:03
db:PACKETSTORMid:81386date:2009-09-16T23:12:39
db:CNNVDid:CNNVD-200905-169date:2009-02-13T00:00:00
db:NVDid:CVE-2009-0153date:2009-05-13T15:30:00.360