CVE-2018-12547

Related Vulnerabilities: CVE-2018-12547  

Impact: Critical Public Date: 2019-03-01 CWE: CWE-120 Bugzilla: 1685611: CVE-2018-12547 IBM JDK: buffer overflow in jio_snprintf() and jio_vsnprintf() In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects existing APIs that called the functions to exceed the allocated buffer. This functions were not directly callable by non-native user code.

The MITRE CVE dictionary describes this issue as:

In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects existing APIs that called the functions to exceed the allocated buffer. This functions were not directly callable by non-native user code.

Find out more about CVE-2018-12547 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 8.8
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality High
Integrity Impact High
Availability Impact High

Affected Packages State

Platform Package State
Red Hat Satellite 5 java-1.8.0-ibm Affected
Red Hat Enterprise Linux 7 java-1.7.1-ibm Affected
Red Hat Enterprise Linux 7 java-1.8.0-ibm Affected
Red Hat Enterprise Linux 6 java-1.7.1-ibm Affected
Red Hat Enterprise Linux 6 java-1.8.0-ibm Affected