Description
UTF32Encoding.cpp in POCO has a Poco::UTF32Encoding integer overflow and resultant stack buffer overflow because Poco::UTF32Encoding::convert() and Poco::UTF32::queryConvert() may return a negative integer if a UTF-32 byte sequence evaluates to a value of 0x80000000 or higher. This is fixed in 1.11.8p2, 1.12.5p2, and 1.13.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4024-1 | poco security update |
References
History
Thu, 29 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Jan 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-29T15:11:56.786Z
Reserved: 2024-01-27T00:00:00.000Z
Link: CVE-2023-52389
Updated: 2025-01-20T17:02:40.241Z
Status : Modified
Published: 2024-01-27T03:15:07.883
Modified: 2025-05-29T16:15:30.857
Link: CVE-2023-52389
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA