REDHAT-BUG-2221634: Medium severity OpenJDK Libraries vulnerability
It was discovered that the ZipFile class implementation in the Libraries component of OpenJDK failed to properly handle ZIP archives that contain a negative value in the uncompressed size and compressed size fields. A specially crafted ZIP file could cause a Java application to enter an infinite loop when extracting data from such archive.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2221634?
REDHAT-BUG-2221634 has been classified with a high severity due to the potential for denial of service in Java applications.
How do I fix REDHAT-BUG-2221634?
To address REDHAT-BUG-2221634, you should update to the latest secure version of OpenJDK that contains the patch.
What types of applications are affected by REDHAT-BUG-2221634?
REDHAT-BUG-2221634 affects Java applications utilizing the OpenJDK Libraries for handling ZIP files.
Can REDHAT-BUG-2221634 lead to data loss?
While REDHAT-BUG-2221634 primarily poses a denial of service threat, it may indirectly lead to data loss if an application is compromised.
Is my system at risk if I use OpenJDK Libraries for ZIP file processing and REDHAT-BUG-2221634 is unpatched?
Yes, using unpatched OpenJDK Libraries for processing ZIP files can expose your system to infinite loop vulnerabilities as described in REDHAT-BUG-2221634.