← Back

CVE-2019-17639

nvd nist
Published: Jul 15, 2020Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer than the length of the source or destination array can, in certain specially crafted code patterns, cause the current method to return prematurely with an undefined return value. This allows whatever value happens to be in the return register at that time to be used as if it matches the method's declared return type.

Affected (4)

Products: Eclipse: Openj9
1 product
Openj9
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Eclipse
Up to 0.20.0
Version 0.21.0
Version 0.21.0 milestone1
Version 0.21.0 milestone2

References (2)

Source: emo@eclipse.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.