CVE-2019-17639
published 2020-07-15CVE-2019-17639: In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer than the length of the source or…
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
1.50%
71.4th percentile
In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer than the length of the source or destination array can, in certain specially crafted code patterns, cause the current method to return prematurely with an undefined return value. This allows whatever value happens to be in the return register at that time to be used as if it matches the method's declared return type.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| eclipse | openj9 | <= 0.20.0 | — |
| eclipse | openj9 | — | — |
| the_eclipse_foundation | eclipse_openj9 | <= 0.21 | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rm33-h23j-qcgg: In Eclipse OpenJ9 prior to version 0
ghsa_unreviewed·2022-05-24
CVE-2019-17639 [HIGH] GHSA-rm33-h23j-qcgg: In Eclipse OpenJ9 prior to version 0
In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer than the length of the source or destination array can, in certain specially crafted code patterns, cause the current method to return prematurely with an undefined return value. This allows whatever value happens to be in the return register at that time to be used as if it matches the method's declared return type.
Red Hat
JDK: Information disclosure via calls to System.arraycopy() with invalid length
vendor_redhat·2020-08-05·CVSS 5.3
CVE-2019-17639 [MEDIUM] CWE-200 JDK: Information disclosure via calls to System.arraycopy() with invalid length
JDK: Information disclosure via calls to System.arraycopy() with invalid length
In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer than the length of the source or destination array can, in certain specially crafted code patterns, cause the current method to return prematurely with an undefined return value. This allows whatever value happens to be in the return register at that time to be used as if it matches the method's declared return type.
Package: java-1.8.0-ibm (Red Hat Enterprise Linux 6) - Will not fix
No detection rules found.
No public exploits indexed.
2020-07-15
Published