JDK: Out-of-bounds access in the String.getBytes method
Published Jul 17, 2019
9.8
CRITICALCVSS 3.0
EPSS 2.10%
Description
In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a byte array within Java code run under a SecurityManager.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<0.15.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The Eclipse Foundation | Eclipse OpenJ9 | n/a |
|
No data.
Red Hat Enterprise Linux 6 Supplementary
java-1.8.0-ibm-1:1.8.0.5.40-1jpp.1.el6_10
Fixed · RHSA-2019:2592
Red Hat Enterprise Linux 7 Supplementary
java-1.8.0-ibm-1:1.8.0.5.40-1jpp.1.el7
Fixed · RHSA-2019:2585
Red Hat Enterprise Linux 8
java-1.8.0-ibm-1:1.8.0.5.40-3.el8_0
Fixed · RHSA-2019:2590
Red Hat Satellite 5.8
java-1.8.0-ibm-1:1.8.0.5.40-1jpp.1.el6_10
Fixed · RHSA-2019:2737
Red Hat Enterprise Linux 6
java-1.7.1-ibm
Not affected
Red Hat Enterprise Linux 7
java-1.7.1-ibm
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Supplementary | java-1.8.0-ibm-1:1.8.0.5.40-1jpp.1.el6_10 | Fixed | RHSA-2019:2592 |
| Red Hat Enterprise Linux 7 Supplementary | java-1.8.0-ibm-1:1.8.0.5.40-1jpp.1.el7 | Fixed | RHSA-2019:2585 |
| Red Hat Enterprise Linux 8 | java-1.8.0-ibm-1:1.8.0.5.40-3.el8_0 | Fixed | RHSA-2019:2590 |
| Red Hat Satellite 5.8 | java-1.8.0-ibm-1:1.8.0.5.40-1jpp.1.el6_10 | Fixed | RHSA-2019:2737 |
| Red Hat Enterprise Linux 6 | java-1.7.1-ibm | Not affected | n/a |
| Red Hat Enterprise Linux 7 | java-1.7.1-ibm | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/errata/RHSA-2019:2585 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:2590 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:2592 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:2737 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-11772 Vendor Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=549075 x_refsource_CONFIRMPermissions RequiredVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1738547 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-3440 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-11772
- https://www.cve.org/CVERecord?id=CVE-2019-11772
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2019:2585 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2019:2590 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2019:2592 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2019:2737 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2019-11772 | Vendor Advisory | |
| https://bugs.eclipse.org/bugs/show_bug.cgi?id=549075 | x_refsource_CONFIRMPermissions RequiredVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1738547 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-3440 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-11772 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-11772 |
Change history (0)
No recorded changes yet.