REDHAT-BUG-2041785: Integer Overflow
An integer overflow flaw was found in the fix applied to the BMPImageReader class implementation in the ImageIO component of OpenJDK to address the CVE-2021-35586 (bug 2015308) issue. This issue could allow a specially-crafted BMP image to bypass previously applied protection and cause a Java application to allocate an excessive amount of memory when opened.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2041785?
The severity of REDHAT-BUG-2041785 is considered high due to the potential for integer overflow exploits.
How do I fix REDHAT-BUG-2041785?
To fix REDHAT-BUG-2041785, apply the latest patches for the OpenJDK ImageIO component.
What versions of OpenJDK ImageIO are affected by REDHAT-BUG-2041785?
REDHAT-BUG-2041785 affects multiple versions of OpenJDK ImageIO before the patches were applied.
What is the nature of the vulnerability in REDHAT-BUG-2041785?
The nature of the vulnerability in REDHAT-BUG-2041785 is an integer overflow flaw that affects image processing.
Is there a public disclosure for REDHAT-BUG-2041785?
Yes, REDHAT-BUG-2041785 has been publicly disclosed and detailed in the Red Hat bug tracking system.