Bugzilla – Bug 1219269
VUL-0: CVE-2023-52389: poco: integer overflow in Poco::UTF32Encoding
Last modified: 2024-03-12 15:52:53 UTC
UTF32Encoding.cpp in POCO has a Poco::UTF32Encoding integer overflow and resultant stack buffer overflow because Poco::UTF32Encoding::convert() and Poco::UTF32::queryConvert() may return a negative integer if a UTF-32 byte sequence evaluates to a value of 0x80000000 or higher. This is fixed in 1.11.8p2, 1.12.5p2, and 1.13.0. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-52389 https://www.cve.org/CVERecord?id=CVE-2023-52389 https://github.com/pocoproject/poco/compare/poco-1.12.5p2-release...poco-1.13.0-release https://github.com/pocoproject/poco/issues/4320 https://pocoproject.org/blog/?p=1226
Factory and Backports codestreams affected.
Factory has newer version. I believe Leap needs a fix. Assigning to new maintainer.