Bug 1685611 (CVE-2018-12547)
| Summary: | CVE-2018-12547 IBM JDK: buffer overflow in jio_snprintf() and jio_vsnprintf() | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Tomas Hoger <thoger> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | urgent | Docs Contact: | |
| Priority: | urgent | ||
| Version: | unspecified | CC: | abergmann, bkearney, java-qa, meissner, sparks, tlestach |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2019-05-16 16:24:16 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1685111, 1685112, 1685113, 1685114, 1685115, 1685116, 1685117, 1689835, 1694579 | ||
| Bug Blocks: | 1661579 | ||
|
Description
Tomas Hoger
2019-03-05 16:18:18 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Supplementary Via RHSA-2019:0469 https://access.redhat.com/errata/RHSA-2019:0469 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Supplementary Via RHSA-2019:0472 https://access.redhat.com/errata/RHSA-2019:0472 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Supplementary Via RHSA-2019:0473 https://access.redhat.com/errata/RHSA-2019:0473 This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Supplementary Via RHSA-2019:0474 https://access.redhat.com/errata/RHSA-2019:0474 Statement: This issue affects the versions of the java-1.8.0-ibm package as shipped with Red Hat Satellite 5. However, OpenJ9 is loaded only by taskomatic and Tomcat. These 2 processes are listening on the loopback interface only. This flaw is not known to be remotely exploitable under any supported scenario in Satellite 5. This issue has been addressed in the following products: Red Hat Satellite 5.8 Via RHSA-2019:0640 https://access.redhat.com/errata/RHSA-2019:0640 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2019:1238 https://access.redhat.com/errata/RHSA-2019:1238 |