CVE-2023-52389
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 27, 2024
Updated: Feb 8, 2024
CWE ID 190
Summary
CVE-2023-52389 is a vulnerability affecting POCO's UTF32Encoding.cpp module. The issue stems from an integer overflow in the Poco::UTF32Encoding::convert() and Poco::UTF32::queryConvert() functions. When processing certain UTF-32 byte sequences that evaluate to values of 0x80000000 or higher, these functions may return a negative integer, resulting in a stack buffer overflow. This vulnerability has been addressed in the patches 1.11.8p2, 1.12.5p2, and 1.13.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share