[DSA 5951-1] icu security update

Moritz Muehlenhoff <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5951-1                   [email protected]
https://www.debian.org/security/                       Moritz Muehlenhoff
June 26, 2025                         https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : icu
CVE ID         : CVE-2025-5222

A buffer overflow was discovered in the International Components for
Unicode (ICU) library.

For the stable distribution (bookworm), this problem has been fixed in
version 72.1-3+deb12u1.

We recommend that you upgrade your icu packages.

For the detailed security status of icu please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/icu

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmhdtWAACgkQEMKTtsN8
TjY6xxAApA/OPUqPWxrD7C3B9UZl1pwk/MgxtecOcEs0VEe8+TmUu7un7EJi81Sh
/dFHAJIdNzR5cp/K1BjPHBS3j9WaB/1t6JuvSfxCZwqUgjSZLljjurv9OBOKmGZW
YYt2j/ti5Jhnu66ZTZYwQg/jTfeNLeHqrcxo1GPAml/R8s6zqnLPOjs5bsqn8q0L
0e6Ezf6YEGA773zJeX0PR0NMeV/In2iFDKPnjhyMLeqN6Rn/JoFIywaWkX1kSRIQ
mTJmvfbfUd3zgSkscu98ZvxWFIRb7uq3WWdzY6gTc/uIrJWHZCgtxP/zh9AIW8eA
EGVWEQDMShZpe7qj9zcSl2M0lOgjtglUEQEqWBf+hj11v5MHiTHx+9dFLjWAn4Qz
JTDu9Qwg79LYk7f1M/t1s3GNAftLmq0SxdzGsFLScLPUM1ZXhr0Ez42aQ8oIFFOo
d9rVItlsCxHbJ/GgWkVB9Tw7TiOhSxFX+Iq3jGL/nVueL1E6/EpiVT8rspZHPYG5
AhYTGQ033ZwEKbyxYwZesvmz1ozcBQMh1zNwuC7EDjXza4ZZyRARqjYNZ0cIJvyP
QMIciSZqL2ZxeOBwgqAKKT68Ivc+GJLqbiDJkDKq6IBemvJRBAw/fxNSu3lTKTuI
fk8PR3813cXNgAVMZg7lhKReIuR8KT9u3zbXZS+9rX5Q2UT/Q9s=
=vkr9
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.