An issue was discovered in ReadyTalk Avian 1.2.0. The vm::arrayCopy method defined in classpath-common.h contains multiple boundary checks that are performed to prevent out-of-bounds memory read/write. However, two of these boundary checks contain an integer overflow that leads to a bypass of these checks, and out-of-bounds read/write. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
References
Link Resource
http://seclists.org/fulldisclosure/2020/Aug/8 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2020/Sep/11 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2020/Sep/13 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2020/Sep/14 Mailing List Third Party Advisory
https://github.com/ReadyTalk/avian/issues Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-08-12T17:30:53

Updated: 2024-06-26T19:56:15.750Z

Reserved: 2020-08-05T00:00:00


Link: CVE-2020-17360

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2020-08-12T18:15:17.340

Modified: 2024-06-26T20:15:13.853


Link: CVE-2020-17360

JSON object: View

cve-icon Redhat Information

No data.