First published: Sun Oct 13 2019(Updated: )
A NULL pointer dereference flaw was discovered in the DrawGlyphList class in the 2D component in OpenJDK. A specially crafted font file could use this flaw to cause a Java application to crash.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.8.0-openjdk-1:1.8.0.232.b09-1.el6_10 | 1.8.0-openjdk-1:1.8.0.232.b09-1.el6_10 |
redhat/java | <1.7.0-openjdk-1:1.7.0.241-2.6.20.0.el6_10 | 1.7.0-openjdk-1:1.7.0.241-2.6.20.0.el6_10 |
redhat/java | <1.7.1-ibm-1:1.7.1.4.55-1jpp.1.el6_10 | 1.7.1-ibm-1:1.7.1.4.55-1jpp.1.el6_10 |
redhat/java | <1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el6_10 | 1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el6_10 |
redhat/java | <11-openjdk-1:11.0.5.10-0.el7_7 | 11-openjdk-1:11.0.5.10-0.el7_7 |
redhat/java | <1.8.0-openjdk-1:1.8.0.232.b09-0.el7_7 | 1.8.0-openjdk-1:1.8.0.232.b09-0.el7_7 |
redhat/java | <1.7.0-openjdk-1:1.7.0.241-2.6.20.0.el7_7 | 1.7.0-openjdk-1:1.7.0.241-2.6.20.0.el7_7 |
redhat/java | <1.7.1-ibm-1:1.7.1.4.55-1jpp.1.el7 | 1.7.1-ibm-1:1.7.1.4.55-1jpp.1.el7 |
redhat/java | <1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el7 | 1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el7 |
redhat/java | <1.8.0-openjdk-1:1.8.0.232.b09-0.el8_0 | 1.8.0-openjdk-1:1.8.0.232.b09-0.el8_0 |
redhat/java | <11-openjdk-1:11.0.5.10-0.el8_0 | 11-openjdk-1:11.0.5.10-0.el8_0 |
redhat/java | <1.8.0-ibm-1:1.8.0.6.0-3.el8_1 | 1.8.0-ibm-1:1.8.0.6.0-3.el8_1 |
debian/openjdk-11 | 11.0.24+8-2~deb11u1 11.0.25~5ea-1 | |
debian/openjdk-8 | 8u422-b05-1 | |
IBM Cognos Controller | <=IBM Cognos Controller 10.4.2 | |
IBM Cognos Controller | <=IBM Cognos Controller 10.4.0 | |
Oracle Java SE 7 | =1.7.0-update231 | |
Oracle Java SE 7 | =1.8.0-update221 | |
Oracle Java SE 7 | =11.0.4 | |
Oracle Java SE 7 | =13.0.0 | |
Oracle JRE | =1.7.0-update231 | |
Oracle JRE | =1.8.0-update221 | |
Oracle JRE | =11.0.4 | |
Oracle JRE | =13.0.0 | |
Red Hat Satellite | =5.8 | |
Red Hat Enterprise Linux | =8.0 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server EUS | =7.7 | |
Red Hat Enterprise Linux Server EUS | =8.1 | |
Red Hat Enterprise Linux Server EUS | =8.6 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Server | =7.7 | |
Red Hat Enterprise Linux Server | =7.7 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Red Hat Enterprise Linux Workstation | =7.0 | |
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.50.2 | |
NetApp SANtricity Storage Manager | ||
NetApp SANtricity Unified Manager | ||
NetApp E-Series SANtricity Web Services | ||
NetApp OnCommand Workflow Automation | ||
NetApp SnapManager for Oracle | ||
NetApp SnapManager for SAP | ||
Debian Linux | =8.0 | |
Debian Linux | =9.0 | |
Debian Linux | =10.0 | |
SUSE Linux | =15.0 | |
SUSE Linux | =15.1 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =19.04 | |
Ubuntu | =19.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2019-2962 is classified as a moderate severity vulnerability.
To fix CVE-2019-2962, update your Java installation to the specified remedial versions provided for OpenJDK and IBM Java.
CVE-2019-2962 affects various versions of OpenJDK and IBM Java running on supported Red Hat Enterprise Linux systems.
Yes, CVE-2019-2962 can lead to crashing Java applications when they process specially crafted font files.
It is essential to update to Java versions 1.8.0-openjdk-1:1.8.0.232.b09 or later, depending on your specific distribution.