Stack-based buffer overflow in the _canonicalize function in common/uloc.c in International Components for Unicode (ICU) before 49.1 allows remote attackers to execute arbitrary code via a crafted locale ID that is not properly handled during variant canonicalization.
| Software | From | Fixed in |
|---|---|---|
| icu-project / international_components_for_unicode | - | 49.1 |