Ubuntu Security Notice 846-1 – It was discovered that ICU did not properly handle invalid byte sequences during Unicode conversion. If an application using ICU processed crafted data, content security mechanisms could be bypassed, potentially leading to cross-site scripting (XSS) attacks.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/81881/USN-846-1.txt
Source: https://packetstormsecurity.com/files/81881/Ubuntu-Security-Notice-846-1.html