In Eclipse OMR versions 0.2.0 to 0.4.0, some of the z/OS atoe print functions use a constant length buffer for string conversion. If the input format string and arguments are larger than the buffer size then buffer overflow occurs. Beginning in version 0.5.0, the conversion buffers are sized correctly and checked appropriately to prevent buffer overflows.
References
Link | Resource |
---|---|
https://github.com/eclipse-omr/omr/pull/7658 | Patch Vendor Advisory |
https://gitlab.eclipse.org/security/cve-assignement/-/issues/55 | Issue Tracking Vendor Advisory |
Configurations
History
05 Mar 2025, 18:54
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:eclipse:omr:*:*:*:*:*:*:*:* | |
References | () https://github.com/eclipse-omr/omr/pull/7658 - Patch, Vendor Advisory | |
References | () https://gitlab.eclipse.org/security/cve-assignement/-/issues/55 - Issue Tracking, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
Summary |
|
|
First Time |
Eclipse omr
Eclipse |
21 Feb 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-21 10:15
Updated : 2025-03-05 18:54
NVD link : CVE-2025-1471
Mitre link : CVE-2025-1471
CVE.ORG link : CVE-2025-1471
JSON object : View
Products Affected
eclipse
- omr
CWE
CWE-787
Out-of-bounds Write