CVE-2020-14593: Buffer Overflow
A flaw was found in the way the imaging library in the 2D component of OpenJDK performed affine transformations of images. An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions.
Other sources
An unspecified vulnerability in Java SE related to the 2D component could allow an unauthenticated attacker to cause no confidentiality impact, high integrity impact, and no availability impact.
— IBM
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.4 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N).
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-14593?
CVE-2020-14593 is classified as a medium severity vulnerability.
How do I fix CVE-2020-14593?
To fix CVE-2020-14593, upgrade to the specific remedied versions of OpenJDK or JRE listed in the vulnerability details.
What versions of Java are affected by CVE-2020-14593?
CVE-2020-14593 affects multiple versions of OpenJDK and Oracle Java, including 1.7 and 1.8 as well as 11.x versions.
What type of vulnerability is CVE-2020-14593?
CVE-2020-14593 is an imaging library vulnerability that can allow untrusted Java applications to bypass sandbox restrictions.
Can CVE-2020-14593 lead to remote code execution?
CVE-2020-14593 does not directly lead to remote code execution but may allow exploitation by bypassing security restrictions.