Vulnerability Description
In Eclipse OpenJ9 up to and including version 0.23, there is potential for a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encoding.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eclipse | Openj9 | <= 0.23.0 |
Related Weaknesses (CWE)
References
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=569763Issue TrackingVendor Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=569763Issue TrackingVendor Advisory
FAQ
What is CVE-2020-27221?
CVE-2020-27221 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Eclipse OpenJ9 up to and including version 0.23, there is potential for a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encodi...
How severe is CVE-2020-27221?
CVE-2020-27221 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-27221?
Check the references section above for vendor advisories and patch information. Affected products include: Eclipse Openj9.