First published: Tue Apr 30 2019(Updated: )
IBM JDK 7 SR10 FP45 (7.0.10.45), 7.1 SR4 FP45 (7.1.4.45), and 8 SR5 FP35 (8.0.5.35) fix a flaw described by upstream as: Eclipse OpenJ9 is vulnerable to a denial of service, caused by the execution of a method past the end of bytecode array by the Java bytecode verifier. A remote attacker could exploit this vulnerability to cause the application to crash. OpenJ9 upstream bug: <a href="https://bugs.eclipse.org/bugs/show_bug.cgi?id=545588">https://bugs.eclipse.org/bugs/show_bug.cgi?id=545588</a> OpenJ9 upstream merge requests: <a href="https://github.com/eclipse/openj9/pull/5528">https://github.com/eclipse/openj9/pull/5528</a> <a href="https://github.com/eclipse/openj9/pull/5529">https://github.com/eclipse/openj9/pull/5529</a> References: <a href="https://www-01.ibm.com/support/docview.wss?uid=ibm10882850">https://www-01.ibm.com/support/docview.wss?uid=ibm10882850</a> <a href="https://developer.ibm.com/javasdk/support/security-vulnerabilities/#IBM_Security_Update_April_2019">https://developer.ibm.com/javasdk/support/security-vulnerabilities/#IBM_Security_Update_April_2019</a>
Affected Software | Affected Version | How to fix |
---|---|---|
IBM JDK 8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1704799 is classified as a denial of service vulnerability.
To fix REDHAT-BUG-1704799, upgrade to IBM JDK 7 SR10 FP45, 7.1 SR4 FP45, or 8 SR5 FP35.
The affected versions include IBM JDK 7 SR10 FP45, 7.1 SR4 FP45, and 8 SR5 FP35.
Yes, REDHAT-BUG-1704799 can be exploited remotely by attackers to cause a denial of service.
Eclipse OpenJ9 Java bytecode verifier is primarily involved in the vulnerability described by REDHAT-BUG-1704799.