CVE-2014-8146

Apple Itunes < 12.1.3 - Memory Corruption

Title source: rule

Description

The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 does not properly track directionally isolated pieces of text, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via crafted text.

Exploits (1)

exploitdb WRITEUP
localmultiple
https://www.exploit-db.com/exploits/43887

Scores

EPSS 0.2581
EPSS Percentile 96.2%

Classification

CWE
CWE-119
Status draft

Affected Products (5)

apple/itunes < 12.1.3
apple/iphone_os < 8.2
apple/mac_os_x < 10.10.4
apple/watchos < 1.0.1
icu-project/international_components_for_unicode < 55.1

Timeline

Published May 25, 2015
Tracked Since Feb 18, 2026