CVE-2019-10245

MEDIUM

Description

In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detects this case and rejects the attempted class load.

References

http://www.securityfocus.com/bid/108094

https://access.redhat.com/errata/RHSA-2019:1163

https://access.redhat.com/errata/RHSA-2019:1164

https://access.redhat.com/errata/RHSA-2019:1165

https://access.redhat.com/errata/RHSA-2019:1166

https://access.redhat.com/errata/RHSA-2019:1238

https://access.redhat.com/errata/RHSA-2019:1325

https://bugs.eclipse.org/bugs/show_bug.cgi?id=545588

Details

Source: MITRE

Published: 2019-04-19

Updated: 2019-06-04

Type: CWE-20

Risk Information

CVSS v2.0

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3.0

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 3.9

Severity: HIGH