Eclipse OpenJ9 °²È«·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-07-03

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-12547£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


IBM and Eclipse Foundation OpenJ9 0.11


·ì϶¸ÅÊö


OpenJ9ÊÇIBM×Ô1997ÄêÒÔÀ´Ò»ÏòÖ÷ÍÆµÄ¸ß»úÄÜJVM²úÆ·£¬£¬£¬£¬£¬£¬ÊÇIBM Java²úÆ·ÖеÄÖ÷Ìâ×é¼þ£¬£¬£¬£¬£¬£¬ÏÕЩËùÓÐIBM³ÉÊì²úÆ·¶¼ÒÀÀµÓÚOpenJ9£¬£¬£¬£¬£¬£¬Òò¶ø½öIBM×ÔÖ÷²úÆ·¾ÍÓÐ400+Êܵ½´Ë·ì϶ӰÏ죬£¬£¬£¬£¬£¬¾ßÌåÁбí¼ûÁ´½Ó£ºhttps://exchange.xforce.ibmcloud.com/vulnerabilities/157512¡£¡£¡£¡£¡£¡£¡£²»½öIBMµÄÈ«Ïß²úÆ·ÒÀÀµOpenJ9£¬£¬£¬£¬£¬£¬ÒòÆäÔÚ2017ÄêÒÑ¿ªÔ´£¬£¬£¬£¬£¬£¬ÎÞÊý×êÓª»úÄܵĵÚÈý·½Ê¢ÐÐÈí¼þÒ²¶¼ÆðͷʹÓÃOpenJ9¡£¡£¡£¡£¡£¡£¡£


¸Ã·ì϶ÊôÓÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬³öÎÊÌâµÄÊÇOpenJ9µÄ»ù´¡º¯Êýjio_snprintf()ºÍjio_vsnprintf()£¬£¬£¬£¬£¬£¬ÓÉÓÚ²»×ã¶Ô²ÎÊý³¤¶ÈµÄÑϸñ²é³­£¬£¬£¬£¬£¬£¬µ¼ÖÂÄܹ»Ö´ÐÐËÁÒâºÅÁîÉõÖÁ»ñµÃ²Ù×÷ϵͳrootȨÏÞ¡£¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£


½¨¸´½¨Òé


IBMÒÑÍÆ³ö²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬½¨ÒéÓû§Éý¼¶OpenJ9µ½×îа汾¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://exchange.xforce.ibmcloud.com/vulnerabilities/157512