PT-2018-2610 · Eclipse+4 · Eclipse Openj9+4

Dan Heidinga

·

Published

2018-04-16

·

Updated

2019-05-16

·

CVE-2018-12547

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Eclipse OpenJ9 versions prior to 0.12.0 libjpeg (affected versions not specified)
Description The issue is related to buffer overflow in the jio snprintf and jio vsnprintf functions of Eclipse OpenJ9, which can be exploited by a remote attacker to impact the confidentiality, integrity, and availability of protected information. In Eclipse OpenJ9, the jio snprintf() and jio vsnprintf() native methods ignored the length parameter, affecting existing APIs that called these functions to exceed the allocated buffer. Additionally, libjpeg is vulnerable to a denial of service caused by a divide-by-zero error in the alloc sarray function, which can be exploited by a remote attacker to cause the application to crash by persuading a victim to open a specially-crafted file.
Recommendations For Eclipse OpenJ9 versions prior to 0.12.0, update to version 0.12.0 or later to resolve the issue. For libjpeg, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01161
CESA-2019_1238
CVE-2018-12547
RHSA-2019:0469
RHSA-2019:0472
RHSA-2019:0473
RHSA-2019:0474
RHSA-2019:0640
RHSA-2019:1238
RHSA-2019_0469
RHSA-2019_0472
RHSA-2019_0473
RHSA-2019_0474
RHSA-2019_1238

Affected Products

Centos
Eclipse Openj9
Ibm Aix
Red Hat
Libjpeg