← Vulnerability feed

Vulnerability record · CVE-2011-4599 · published 21 June 2012

CVE-2011-4599: Icu-project international components for unicode memory buffer overflow vulnerability

Icu Project · International Components For Unicode

Stack-based buffer overflow in the _canonicalize function in common/uloc.c in International Components for Unicode (ICU) before 49.1 allows remote attackers to execute arbitrary code via a crafted locale ID that is not properly handled during variant canonicalization.

7.5 CVSS 2.0 High EPSS 8.0% · top 5.4% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
8.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
42References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the _canonicalize function in common/uloc.c in International Components for Unicode (ICU) before 49.1 allows remote attackers to execute arbitrary code via a crafted locale ID that is not properly handled during variant canonicalization.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugs.icu-project.org/trac/ticket/8984 Issue TrackingVendor Advisory
http://code.google.com/p/chromium/issues/detail?id=106441 Third Party Advisory
http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html Mailing ListThird Party Advisory
http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-updates/2012-01/msg00035.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2011-1815.html Third Party Advisory
http://secunia.com/advisories/47146 Permissions Required
http://secunia.com/advisories/47227 Permissions Required
http://secunia.com/advisories/47674 Permissions Required
http://secunia.com/advisories/47714 Permissions Required
http://secunia.com/advisories/47775 Permissions Required
http://support.apple.com/kb/HT5501 Third Party Advisory
http://support.apple.com/kb/HT5503 Third Party Advisory
http://ubuntu.com/usn/usn-1348-1 Third Party Advisory
http://www.debian.org/security/2012/dsa-2397 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2011:194 Third Party Advisory
http://www.openwall.com/lists/oss-security/2011/12/09/2 Mailing List
http://www.openwall.com/lists/oss-security/2011/12/09/5 Mailing List
http://www.osvdb.org/77698 Broken Link
http://www.securityfocus.com/bid/51006 PatchThird Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/71726 VDB Entry
http://bugs.icu-project.org/trac/ticket/8984 Issue TrackingVendor Advisory
http://code.google.com/p/chromium/issues/detail?id=106441 Third Party Advisory
http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html Mailing ListThird Party Advisory
http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-updates/2012-01/msg00035.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2011-1815.html Third Party Advisory
http://secunia.com/advisories/47146 Permissions Required
http://secunia.com/advisories/47227 Permissions Required
http://secunia.com/advisories/47674 Permissions Required
http://secunia.com/advisories/47714 Permissions Required
http://secunia.com/advisories/47775 Permissions Required
http://support.apple.com/kb/HT5501 Third Party Advisory
http://support.apple.com/kb/HT5503 Third Party Advisory
http://ubuntu.com/usn/usn-1348-1 Third Party Advisory
http://www.debian.org/security/2012/dsa-2397 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2011:194 Third Party Advisory
http://www.openwall.com/lists/oss-security/2011/12/09/2 Mailing List
http://www.openwall.com/lists/oss-security/2011/12/09/5 Mailing List
http://www.osvdb.org/77698 Broken Link

Track CVE-2011-4599 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2015-5922Apple mac os x vulnerabilityUnspecified vulnerability in International Components for Unicode (ICU) before 53.1.0, as used in Apple OS X before 10.11 and watchOS before 2, has u…EPSS 3.0%9.8CVE-2018-18928Icu-project international components for unicode integer overflow vulnerabilityInternational Components for Unicode (ICU) for C/C++ 63.1 has an integer overflow in number::impl::DecimalQuantity::toScientificString() in i18n/numb…EPSS 2.9%9.8CVE-2017-17484Icu-project international components for unicode memory buffer overflow vulnerabilityThe ucnv_UTF8FromUTF8 function in ucnv_u8.cpp in International Components for Unicode (ICU) for C/C++ through 60.1 mishandles ucnv_convertEx calls fo…EPSS 4.6%9.8CVE-2017-14952Icu-project international components for unicode double free vulnerabilityDouble free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary co…EPSS 5.1%9.8CVE-2014-9654Google chrome memory buffer overflow vulnerabilityThe Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-12-03, as used in Google Chrome before 40.0.2214.…EPSS 2.4%9.8CVE-2014-9911Icu-project international components for unicode memory buffer overflow vulnerabilityStack-based buffer overflow in the ures_getByKeyWithFallback function in common/uresbund.cpp in International Components for Unicode (ICU) before 54.…EPSS 5.5%9.8CVE-2016-7415Icu-project international components for unicode memory buffer overflow vulnerabilityStack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ allows remot…EPSS 5.8%9.8CVE-2016-6293Icu-project international components for unicode memory buffer overflow vulnerabilityThe uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that…EPSS 5.0%

Source: NIST National Vulnerability Database (record CVE-2011-4599), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.