JDK: Information disclosure via calls to System.arraycopy() with invalid length
Published Jul 15, 2020
5.3
MEDIUMCVSS 3.1
EPSS 1.50%
Description
In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer than the length of the source or destination array can, in certain specially crafted code patterns, cause the current method to return prematurely with an undefined return value. This allows whatever value happens to be in the return register at that time to be used as if it matches the method's declared return type.
Affected products
-
- Version <= 0.21StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The Eclipse Foundation | Eclipse OpenJ9 | n/a |
|
No data.
Red Hat Enterprise Linux 6 Supplementary
java-1.7.1-ibm-1:1.7.1.4.70-1jpp.1.el6_10
Fixed · RHSA-2020:3387
Red Hat Enterprise Linux 7 Supplementary
java-1.7.1-ibm-1:1.7.1.4.70-1jpp.1.el7
Fixed · RHSA-2020:3388
Red Hat Enterprise Linux 7 Supplementary
java-1.8.0-ibm-1:1.8.0.6.20-1jpp.1.el7
Fixed · RHSA-2020:5585
Red Hat Enterprise Linux 8
java-1.8.0-ibm-1:1.8.0.6.15-1.el8_2
Fixed · RHSA-2020:3386
Red Hat Enterprise Linux 6
java-1.8.0-ibm
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Supplementary | java-1.7.1-ibm-1:1.7.1.4.70-1jpp.1.el6_10 | Fixed | RHSA-2020:3387 |
| Red Hat Enterprise Linux 7 Supplementary | java-1.7.1-ibm-1:1.7.1.4.70-1jpp.1.el7 | Fixed | RHSA-2020:3388 |
| Red Hat Enterprise Linux 7 Supplementary | java-1.8.0-ibm-1:1.8.0.6.20-1jpp.1.el7 | Fixed | RHSA-2020:5585 |
| Red Hat Enterprise Linux 8 | java-1.8.0-ibm-1:1.8.0.6.15-1.el8_2 | Fixed | RHSA-2020:3386 |
| Red Hat Enterprise Linux 6 | java-1.8.0-ibm | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://access.redhat.com/security/cve/CVE-2019-17639 Vendor Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=563998 x_refsource_CONFIRMVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1866497 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2019-17639
- https://www.cve.org/CVERecord?id=CVE-2019-17639
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-17639 | Vendor Advisory | |
| https://bugs.eclipse.org/bugs/show_bug.cgi?id=563998 | x_refsource_CONFIRMVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1866497 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-17639 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-17639 |
Change history (0)
No recorded changes yet.