Liberica JDK21.0.7+9Security Advisory
Search Cve

CVE-2024-54534

Published: December 26, 2024Last modified: April 18, 2025

Description

The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to memory corruption.

Severity score breakdown

ParameterValue
Base score9.8
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Liberica JDK8jdk-fullFixed (8u452+11)
jre-fullFixed (8u452+11)
11jdk-fullFixed (11.0.27+9)
jre-fullFixed (11.0.27+9)
17jdk-fullFixed (17.0.15+10)
jre-fullFixed (17.0.15+10)
21jdk-fullFixed (21.0.7+9)
jre-fullFixed (21.0.7+9)
24jdk-fullFixed (24.0.1+11)
jre-fullFixed (24.0.1+11)

References

Published BELL-SAs

ON THIS PAGE