JDK: Read beyond the end of bytecode array causing JVM crash
Published Apr 19, 2019
7.5
HIGHCVSS 3.1
EPSS 2.49%
Description
In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detects this case and rejects the attempted class load.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<0.14.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The Eclipse Foundation | Eclipse OpenJ9 | n/a |
|
Configuration 2
- 5.8
- 8.0
- 6.0
- 7.0
- 6.0
- 7.0
- 6.0
- 7.0
No data.
Red Hat Enterprise Linux 6 Supplementary
java-1.7.1-ibm-1:1.7.1.4.45-1jpp.1.el6_10
Fixed · RHSA-2019:1165
Red Hat Enterprise Linux 6 Supplementary
java-1.8.0-ibm-1:1.8.0.5.35-1jpp.1.el6_10
Fixed · RHSA-2019:1163
Red Hat Enterprise Linux 7 Supplementary
java-1.7.1-ibm-1:1.7.1.4.45-1jpp.1.el7
Fixed · RHSA-2019:1166
Red Hat Enterprise Linux 7 Supplementary
java-1.8.0-ibm-1:1.8.0.5.35-1jpp.1.el7
Fixed · RHSA-2019:1164
Red Hat Enterprise Linux 8
java-1.8.0-ibm-1:1.8.0.5.35-3.el8_0
Fixed · RHSA-2019:1238
Red Hat Satellite 5.8
java-1.8.0-ibm-1:1.8.0.5.35-1jpp.1.el6_10
Fixed · RHSA-2019:1325
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Supplementary | java-1.7.1-ibm-1:1.7.1.4.45-1jpp.1.el6_10 | Fixed | RHSA-2019:1165 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.8.0-ibm-1:1.8.0.5.35-1jpp.1.el6_10 | Fixed | RHSA-2019:1163 |
| Red Hat Enterprise Linux 7 Supplementary | java-1.7.1-ibm-1:1.7.1.4.45-1jpp.1.el7 | Fixed | RHSA-2019:1166 |
| Red Hat Enterprise Linux 7 Supplementary | java-1.8.0-ibm-1:1.8.0.5.35-1jpp.1.el7 | Fixed | RHSA-2019:1164 |
| Red Hat Enterprise Linux 8 | java-1.8.0-ibm-1:1.8.0.5.35-3.el8_0 | Fixed | RHSA-2019:1238 |
| Red Hat Satellite 5.8 | java-1.8.0-ibm-1:1.8.0.5.35-1jpp.1.el6_10 | Fixed | RHSA-2019:1325 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- http://www.securityfocus.com/bid/108094 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:1163 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1164 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1165 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1166 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1238 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1325 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-10245 Vendor Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=545588 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1704799 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2019-10245
- https://www.cve.org/CVERecord?id=CVE-2019-10245
Change history (0)
No recorded changes yet.