First published: Mon Oct 19 2020(Updated: )
It was discovered that the Hotspot component of OpenJDK did not properly check for integer overflows when when optimizing code, leading to out-of-bounds access. An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions.
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Build of OpenJDK with Hotspot |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1889280 is considered high due to the potential for bypassing Java sandbox restrictions.
To fix REDHAT-BUG-1889280, update to the latest version of OpenJDK Hotspot that addresses this vulnerability.
The vulnerability REDHAT-BUG-1889280 is caused by improper checking for integer overflows in the Hotspot component of OpenJDK.
Users running untrusted Java applications or applets on systems with vulnerable versions of OpenJDK Hotspot are affected by REDHAT-BUG-1889280.
The potential impacts of REDHAT-BUG-1889280 include unauthorized access and execution of code that could bypass Java security measures.