REDHAT-BUG-1928555: Buffer Overflow
IBM JDK 7 SR10 FP80 (7.0.10.80), 7.1 SR4 FP80 (7.1.4.80), 8 SR6 FP25 (8.0.6.25), and 11 SR10 (11.0.10.0) fix a flaw described by upstream as:
Eclipse OpenJ9 is vulnerable to a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encoding. By sending an overly long string, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
References:
https://www.ibm.com/support/pages/node/6414721 https://www.ibm.com/support/pages/java-sdk-security-vulnerabilities#IBMSecurityUpdateFebruary2021 https://bugs.eclipse.org/bugs/showbug.cgi?id=569763
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1928555?
The severity of REDHAT-BUG-1928555 is considered high due to the potential for a stack-based buffer overflow.
How do I fix REDHAT-BUG-1928555?
To fix REDHAT-BUG-1928555, you should update your IBM JDK or Eclipse OpenJ9 to the latest patched versions provided by IBM.
Which versions are affected by REDHAT-BUG-1928555?
Affected versions of REDHAT-BUG-1928555 include IBM JDK 7 SR10 FP80, 7.1 SR4 FP80, 8 SR6 FP25, and 11 SR10, as well as Eclipse OpenJ9.
What type of vulnerability is REDHAT-BUG-1928555?
REDHAT-BUG-1928555 is classified as a stack-based buffer overflow vulnerability.
Who should address REDHAT-BUG-1928555?
Organizations using affected versions of IBM JDK or Eclipse OpenJ9 must address REDHAT-BUG-1928555 to ensure their systems are secure.