Описание
A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for the argument array before the system call. This can lead to heap corruption and application crashes (DoS).
All versions are believed to be vulnerable. This project is unmaintained at the time of CVE assignment.
A flaw was found in Jansi. A heap buffer overflow vulnerability exists in the Jansi Java Native Interface (JNI) 'ioctl()' wrapper. This is due to a lack of size verification for the argument array before the system call, which can lead to heap corruption. An attacker could exploit this to cause application crashes, resulting in a Denial of Service (DoS).
Отчет
This Moderate vulnerability in Jansi's JNI ioctl() wrapper can lead to a denial of service due to a heap buffer overflow. Exploitation requires local access and user interaction, as the flaw stems from insufficient size verification of the argument array before a system call, potentially causing application instability. The unmaintained status of the Jansi project increases the risk associated with this flaw.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Cryostat 4 | jansi | Fix deferred | ||
| Exploit Intelligence | exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 | Out of support scope | ||
| Migration Toolkit for Applications 8 | mta/mta-cli-rhel9 | Fix deferred | ||
| Migration Toolkit for Applications 8 | mta/mta-java-external-provider-rhel9 | Fix deferred | ||
| OpenShift Developer Tools and Services | jenkins | Out of support scope | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Out of support scope | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel9 | Out of support scope | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | jansi | Fix deferred | ||
| Red Hat build of Apache Camel for Spring Boot 4 | jansi.dll | Fix deferred | ||
| Red Hat build of Apache Camel - HawtIO 4 | jansi | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS3
Связанные уязвимости
A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for the argument array before the system call. This can lead to heap corruption and application crashes (DoS). All versions are believed to be vulnerable. This project is unmaintained at the time of CVE assignment.
A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for the argument array before the system call. This can lead to heap corruption and application crashes (DoS). All versions are believed to be vulnerable. This project is unmaintained at the time of CVE assignment.
A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" ...
A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for the argument array before the system call. This can lead to heap corruption and application crashes (DoS). All versions are believed to be vulnerable. This project is unmaintained at the time of CVE assignment.
EPSS
5 Medium
CVSS3