Eclipse OpenJ9 Çå¾²Îó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-03

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-12547£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


IBM and Eclipse Foundation OpenJ9 0.11


Îó²î¸ÅÊö


OpenJ9ÊÇIBM×Ô1997ÄêÒÔÀ´Ò»Ö±Ö÷ÍÆµÄ¸ßÐÔÄÜJVM²úÆ·£¬£¬£¬£¬£¬ÊÇIBM Java²úÆ·ÖеĽ¹µã×é¼þ£¬£¬£¬£¬£¬ÏÕЩËùÓÐIBM³ÉÊì²úÆ·¶¼ÒÀÀµÓÚOpenJ9£¬£¬£¬£¬£¬Òò´Ë½öIBM×ÔÖ÷²úÆ·¾ÍÓÐ400+Êܵ½´ËÎó²îÓ°Ï죬£¬£¬£¬£¬ÏêϸÁбí¼ûÁ´½Ó£ºhttps://exchange.xforce.ibmcloud.com/vulnerabilities/157512¡£¡£ ¡£¡£¡£²»µ«IBMµÄÈ«Ïß²úÆ·ÒÀÀµOpenJ9£¬£¬£¬£¬£¬ÒòÆäÔÚ2017ÄêÒÑ¿ªÔ´£¬£¬£¬£¬£¬ÎÞÊý×·ÇóÐÔÄܵĵÚÈý·½Ê¢ÐÐÈí¼þÒ²¶¼×îÏÈʹÓÃOpenJ9¡£¡£ ¡£¡£¡£


¸ÃÎó²îÊôÓÚ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬³öÎÊÌâµÄÊÇOpenJ9µÄ»ù´¡º¯Êýjio_snprintf()ºÍjio_vsnprintf()£¬£¬£¬£¬£¬ÓÉÓÚȱ·¦¶Ô²ÎÊý³¤¶ÈµÄÑÏ¿á¼ì²é£¬£¬£¬£¬£¬µ¼Ö¿ÉÒÔÖ´ÐÐí§ÒâÏÂÁîÉõÖÁ»ñµÃ²Ù×÷ϵͳrootȨÏÞ¡£¡£ ¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£ ¡£¡£¡£


ÐÞ¸´½¨Òé


IBMÒÑÍÆ³ö²¹¶¡£¡£ ¡£¡£¡£¬£¬£¬£¬£¬½¨ÒéÓû§Éý¼¶OpenJ9µ½×îа汾¡£¡£ ¡£¡£¡£


²Î¿¼Á´½Ó


https://exchange.xforce.ibmcloud.com/vulnerabilities/157512