Vulnerability Description
In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detects this case and rejects the attempted class load.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eclipse | Openj9 | < 0.14.0 |
| Redhat | Satellite | 5.8 |
| Redhat | Enterprise Linux | 8.0 |
| Redhat | Enterprise Linux Desktop | 6.0 |
| Redhat | Enterprise Linux Server | 6.0 |
| Redhat | Enterprise Linux Workstation | 6.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/108094Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:1163Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1164Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1165Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1166Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1238Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1325Third Party Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=545588Issue TrackingPatchThird Party Advisory
- http://www.securityfocus.com/bid/108094Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:1163Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1164Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1165Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1166Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1238Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1325Third Party Advisory
FAQ
What is CVE-2019-10245?
CVE-2019-10245 is a vulnerability with a CVSS score of 7.5 (HIGH). In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detect...
How severe is CVE-2019-10245?
CVE-2019-10245 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10245?
Check the references section above for vendor advisories and patch information. Affected products include: Eclipse Openj9, Redhat Satellite, Redhat Enterprise Linux, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server.