Logo
vulnerabilityCVE-2023-52389
Name
CVE-2023-52389
Source
NVD ( link)Debian ( link)
Description
UTF32Encoding.cpp in POCO has a Poco::UTF32Encoding integer overflow and resultant stack buffer overflow because Poco::UTF32Encoding::convert() and Poco::UTF32::queryConvert() may return a negative integer if a UTF-32 byte sequence evaluates to a value of 0x80000000 or higher. This is fixed in 1.11.8p2, 1.12.5p2, and 1.13.0.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
poco
Exploitable

Vulnerability Ratings#


9.8
CVSSv31
9.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.13.2
Not Affected
buildroot
master
1.14.2
Not Affected
openwrt
openwrt-25.12
1.11.0-r2
Exploitable
yocto
kirkstone
1.11.2
Patched
yocto
master
1.15.3
Not Affected
yocto
scarthgap
1.12.5p2
Not Affected

Resolved with patches#


poco (yocto:kirkstone)

#
Title
Author
Resolve
1
Fix Integer overflow in Poco::UTF32Encoding
Andrei Fedotov <anfedotoff@yandex-team.ru>
CVE-2023-52389