漏洞标题
Eclipse OMR: 缓冲区溢出漏洞
漏洞描述信息
在Eclipse OMR版本0.2.0至0.4.0中,部分z/OS atoe打印函数在字符串转换时使用固定长度的缓冲区。如果输入的格式字符串和参数大于缓冲区大小,则会发生缓冲区溢出。从版本0.5.0开始,转换缓冲区的大小设置正确并进行适当检查,以防止缓冲区溢出。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出)
漏洞标题
Eclipse OMR: Buffer overflow vulnerability
漏洞描述信息
In Eclipse OMR versions 0.2.0 to 0.4.0, some of the z/OS atoe print functions use a constant length buffer for string conversion. If the input format string and arguments are larger than the buffer size then buffer overflow occurs. Beginning in version 0.5.0, the conversion buffers are sized correctly and checked appropriately to prevent buffer overflows.
CVSS信息
N/A
漏洞类别
跨界内存写