Vulnerability Description
ThreeTen Backport v1.6.8 was discovered to contain an integer overflow via the component org.threeten.bp.format.DateTimeFormatter::parse(CharSequence, ParsePosition). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.
References
- http://threeten.com
- https://gist.github.com/LLM4IG/d2618f5f4e5ac37eb75cff5617e58b90
- https://github.com/ThreeTen/threetenbp
- http://threeten.com
- https://gist.github.com/LLM4IG/d2618f5f4e5ac37eb75cff5617e58b90
- https://github.com/ThreeTen/threetenbp
FAQ
What is CVE-2024-23082?
CVE-2024-23082 is a documented vulnerability. ThreeTen Backport v1.6.8 was discovered to contain an integer overflow via the component org.threeten.bp.format.DateTimeFormatter::parse(CharSequence, ParsePosition). NOTE: this is disputed by multipl...
How severe is CVE-2024-23082?
CVSS scoring is not yet available for CVE-2024-23082. Check NVD for updates.
Is there a patch for CVE-2024-23082?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.