CVE-2019-2698: High severity Oracle JDK vulnerability
A out of bounds access flaw was found in the font layout engine in the 2D component of OpenJDK. Missing validation of the position value in GlyphIterator::setCurrGlyphID could lead to memory corruption, triggered by a specially crafted font file. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
Other sources
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-2698.
What software is affected by CVE-2019-2698?
The affected software includes Oracle JDK and JRE versions 1.7.0-update211 and 1.8.0-update202, Redhat Openshift Container Platform 3.11, Debian Debian Linux 8.0 and 9.0, openSUSE Leap 15.0 and 42.3, Canonical Ubuntu Linux 16.04, 18.04, 18.10, and 19.04, Redhat Satellite 5.8, Redhat Enterprise Linux versions 6.0, 7.0, 8.0, Redhat Enterprise Linux Desktop versions 6.0 and 7.0, and other variants of Redhat Enterprise Linux.
What is the severity of CVE-2019-2698?
The severity of CVE-2019-2698 is high, with a CVSS score of 8.1.
What is the description of CVE-2019-2698?
CVE-2019-2698 is a vulnerability in the Java SE component of Oracle Java SE that allows an unauthenticated attacker with network access to compromise Java SE via multiple protocols.
How can I fix CVE-2019-2698?
To fix CVE-2019-2698, it is recommended to update to the latest patched versions of the affected software. Please refer to the vendor's website for specific remediation steps.