CVE-2014-8147 is a denial-of-service vulnerability in the Unicode Bidirectional Algorithm implementation of ICU4C in International Components for Unicode (ICU) before version 55.1. It arises from an integer data type inconsistency, allowing remote attackers to trigger an incorrect malloc followed by an invalid free, potentially leading to arbitrary code execution. With a CVSS score of 7.5 (High), this vulnerability is remotely exploitable with low attack complexity, impacting confidentiality, integrity, and availability. While there is no evidence of active exploitation or Metasploit modules, an ExploitDB entry (EDB-43887) suggests exploit code exists for similar ICU library vulnerabilities. Community discussion and media coverage for this specific CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.10.4CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
<= 1.0.1CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* | ||
< 55.1CPE matchmatch criteria | cpe:2.3:a:icu-project:international_components_for_unicode:*:*:*:*:*:c\/c\+\+:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.