In Eclipse OMR versions 0.2.0 to 0.4.0, some of the z/OS atoe print functions use a constant length buffer for string conversion. If the input format string and arguments are larger than the buffer size then buffer overflow occurs. Beginning in version 0.5.0, the conversion buffers are sized correctly and checked appropriately to prevent buffer overflows.
History

Wed, 05 Mar 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Eclipse
Eclipse omr
CPEs cpe:2.3:a:eclipse:omr:*:*:*:*:*:*:*:*
Vendors & Products Eclipse
Eclipse omr
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 25 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Feb 2025 10:15:00 +0000

Type Values Removed Values Added
Description In Eclipse OMR versions 0.2.0 to 0.4.0, some of the z/OS atoe print functions use a constant length buffer for string conversion. If the input format string and arguments are larger than the buffer size then buffer overflow occurs. Beginning in version 0.5.0, the conversion buffers are sized correctly and checked appropriately to prevent buffer overflows.
Title Eclipse OMR: Buffer overflow vulnerability
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published: 2025-02-21T10:07:22.507Z

Updated: 2025-02-25T19:15:22.042Z

Reserved: 2025-02-19T14:44:59.852Z

Link: CVE-2025-1471

cve-icon Vulnrichment

Updated: 2025-02-21T13:45:57.922Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-21T10:15:11.413

Modified: 2025-03-05T18:54:18.150

Link: CVE-2025-1471

cve-icon Redhat

No data.