CVE-2024-10917

In Eclipse OpenJ9 versions up to 0.47, the JNI function GetStringUTFLength may return an incorrect value which has wrapped around. From 0.48 the value is correct but may be truncated to include a smaller number of characters.
Configurations

Configuration 1 (hide)

cpe:2.3:a:eclipse:openj9:*:*:*:*:*:*:*:*

History

09 Jan 2025, 18:08

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
First Time Eclipse openj9
Eclipse
CPE cpe:2.3:a:eclipse:openj9:*:*:*:*:*:*:*:*
References () https://github.com/eclipse-openj9/openj9/releases/tag/openj9-0.48.0 - () https://github.com/eclipse-openj9/openj9/releases/tag/openj9-0.48.0 - Release Notes
References () https://gitlab.eclipse.org/security/cve-assignement/-/issues/47 - () https://gitlab.eclipse.org/security/cve-assignement/-/issues/47 - Issue Tracking, Vendor Advisory
References () https://github.com/eclipse-openj9/openj9/pull/20362 - () https://github.com/eclipse-openj9/openj9/pull/20362 - Issue Tracking, Patch
CWE CWE-190

11 Nov 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-11 17:15

Updated : 2025-01-09 18:08


NVD link : CVE-2024-10917

Mitre link : CVE-2024-10917


JSON object : View

Products Affected

eclipse

  • openj9
CWE
CWE-190

Integer Overflow or Wraparound