CVE-2019-10245

high

Description

In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detects this case and rejects the attempted class load.

References

https://bugs.eclipse.org/bugs/show_bug.cgi?id=545588

http://www.securityfocus.com/bid/108094

https://access.redhat.com/errata/RHSA-2019:1166

https://access.redhat.com/errata/RHSA-2019:1165

https://access.redhat.com/errata/RHSA-2019:1164

https://access.redhat.com/errata/RHSA-2019:1163

https://access.redhat.com/errata/RHSA-2019:1238

https://access.redhat.com/errata/RHSA-2019:1325

Details

Source: MITRE

Published: 2019-04-19

Updated: 2021-10-28

Type: CWE-119

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 3.9

Severity: HIGH