First published: Sun Oct 13 2019(Updated: )
It was discovered that the Font class in the Serialization component in OpenJDK did not properly handle deserialization of certain object attributes and throws an unexpected exception. A Java application desriazlizing an untrusted serialized object stream could possibly terminate unexpectedly because of an unhandled exception.
Affected Software | Affected Version | How to fix |
---|---|---|
OpenJDK 17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1761262 is considered high due to potential application crashes from deserializing untrusted objects.
To fix REDHAT-BUG-1761262, ensure that you update to the latest version of OpenJDK that addresses this vulnerability.
Applications using OpenJDK, particularly those that deserialize untrusted serialized object streams, can be affected by REDHAT-BUG-1761262.
REDHAT-BUG-1761262 primarily results in application crashes rather than a direct remote code execution risk.
REDHAT-BUG-1761262 was discovered in 2019 as part of ongoing vulnerability assessments in OpenJDK.