CVE-2019-17639 Information
Feb 14, 2021
cve
Description
In Eclipse OpenJ9 prior to version 0.21 on Power platforms calling the System.arraycopy method with a length longer than the length of the source or destination array can in certain specially crafted code patterns cause the current method to return prematurely with an undefined return value. This allows whatever value happens to be in the return register at that time to be used as if it matches the method’s declared return type.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
https://bugs.eclipse.org/bugs/show_bug.cgi?id=563998
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: