Eclipse OpenJ9 °²È«·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-07-03·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2018-12547£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8
Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
IBM and Eclipse Foundation OpenJ9 0.11
·ì϶¸ÅÊö
OpenJ9ÊÇIBM×Ô1997ÄêÒÔÀ´Ò»ÏòÖ÷ÍÆµÄ¸ß»úÄÜJVM²úÆ·£¬ÊÇIBM Java²úÆ·ÖеÄÖ÷Ìâ×é¼þ£¬ÏÕЩËùÓÐIBM³ÉÊì²úÆ·¶¼ÒÀÀµÓÚOpenJ9£¬Òò¶ø½öIBM×ÔÖ÷²úÆ·¾ÍÓÐ400+Êܵ½´Ë·ì϶ӰÏ죬¾ßÌåÁбí¼ûÁ´½Ó£ºhttps://exchange.xforce.ibmcloud.com/vulnerabilities/157512¡£²»½öIBMµÄÈ«Ïß²úÆ·ÒÀÀµOpenJ9£¬ÒòÆäÔÚ2017ÄêÒÑ¿ªÔ´£¬ÎÞÊý×êÓª»úÄܵĵÚÈý·½Ê¢ÐÐÈí¼þÒ²¶¼ÆðͷʹÓÃOpenJ9¡£
¸Ã·ì϶ÊôÓÚ»º³åÇøÒç¶Âí½Å£¬³öÎÊÌâµÄÊÇOpenJ9µÄ»ù´¡º¯Êýjio_snprintf()ºÍjio_vsnprintf()£¬ÓÉÓÚ²»×ã¶Ô²ÎÊý³¤¶ÈµÄÑϸñ²é³£¬µ¼ÖÂÄܹ»Ö´ÐÐËÁÒâºÅÁîÉõÖÁ»ñµÃ²Ù×÷ϵͳrootȨÏÞ¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
IBMÒÑÍÆ³ö²¹¶¡£¬½¨ÒéÓû§Éý¼¶OpenJ9µ½×îа汾¡£
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ