First published: Fri Oct 11 2019(Updated: )
An integer overflow flaw was found in the SunGraphics2D class in the 2D component in OpenJDK. The check of offset and length values passed to drawChars() and drawBytes() methods could be bypassed, leading to excessive memory allocation or attempt to access buffer out of bounds.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.8.0-openjdk-1:1.8.0.232.b09-1.el6_10 | 1.8.0-openjdk-1:1.8.0.232.b09-1.el6_10 |
redhat/java | <1.7.0-openjdk-1:1.7.0.241-2.6.20.0.el6_10 | 1.7.0-openjdk-1:1.7.0.241-2.6.20.0.el6_10 |
redhat/java | <1.7.1-ibm-1:1.7.1.4.55-1jpp.1.el6_10 | 1.7.1-ibm-1:1.7.1.4.55-1jpp.1.el6_10 |
redhat/java | <1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el6_10 | 1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el6_10 |
redhat/java | <11-openjdk-1:11.0.5.10-0.el7_7 | 11-openjdk-1:11.0.5.10-0.el7_7 |
redhat/java | <1.8.0-openjdk-1:1.8.0.232.b09-0.el7_7 | 1.8.0-openjdk-1:1.8.0.232.b09-0.el7_7 |
redhat/java | <1.7.0-openjdk-1:1.7.0.241-2.6.20.0.el7_7 | 1.7.0-openjdk-1:1.7.0.241-2.6.20.0.el7_7 |
redhat/java | <1.7.1-ibm-1:1.7.1.4.55-1jpp.1.el7 | 1.7.1-ibm-1:1.7.1.4.55-1jpp.1.el7 |
redhat/java | <1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el7 | 1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el7 |
redhat/java | <1.8.0-openjdk-1:1.8.0.232.b09-0.el8_0 | 1.8.0-openjdk-1:1.8.0.232.b09-0.el8_0 |
redhat/java | <11-openjdk-1:11.0.5.10-0.el8_0 | 11-openjdk-1:11.0.5.10-0.el8_0 |
redhat/java | <1.8.0-ibm-1:1.8.0.6.0-3.el8_1 | 1.8.0-ibm-1:1.8.0.6.0-3.el8_1 |
IBM Engineering Requirements Quality Assistant On-Premises | <=All | |
debian/openjdk-11 | 11.0.24+8-2~deb11u1 11.0.25~5ea-1 | |
debian/openjdk-8 | 8u422-b05-1 | |
Oracle JDK 6 | =1.7.0-update231 | |
Oracle JDK 6 | =1.8.0-update221 | |
Oracle JDK 6 | =11.0.4 | |
Oracle JDK 6 | =13.0.0 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update231 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update221 | |
Oracle Java Runtime Environment (JRE) | =11.0.4 | |
Oracle Java Runtime Environment (JRE) | =13.0.0 | |
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.50.2 | |
netapp e-series santricity storage manager | ||
netapp e-series santricity unified manager | ||
NetApp E-Series SANtricity Web Services Proxy | ||
NetApp OnCommand Workflow Automation | ||
netapp snapmanager Oracle | ||
netapp snapmanager sap | ||
Debian GNU/Linux | =8.0 | |
Debian GNU/Linux | =9.0 | |
Debian GNU/Linux | =10.0 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =19.04 | |
Ubuntu Linux | =19.10 | |
openSUSE | =15.0 | |
openSUSE | =15.1 | |
redhat satellite | =5.8 | |
Red Hat Enterprise Linux | =8.0 | |
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux desktop | =7.0 | |
redhat enterprise Linux eus | =7.7 | |
redhat enterprise Linux eus | =8.1 | |
redhat enterprise Linux eus | =8.6 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux server | =7.0 | |
redhat enterprise Linux server aus | =7.7 | |
redhat enterprise Linux server tus | =7.7 | |
redhat enterprise Linux workstation | =6.0 | |
redhat enterprise Linux workstation | =7.0 | |
Debian | =8.0 | |
Debian | =9.0 | |
Debian | =10.0 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =19.04 | |
Ubuntu | =19.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2019-2988 is a vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D).
Java SE versions 7u231, 8u221, 11.0.4, and 13, as well as Java SE Embedded 8u221, are affected.
An unauthenticated attacker with network access can exploit this vulnerability via multiple protocols.
CVE-2019-2988 has a severity rating of 3.7 (low).
To fix CVE-2019-2988, update your Java SE or Java SE Embedded to the recommended versions listed in the references.