In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.
{
"binaries": [
{
"binary_version": "3.8.1-8",
"binary_name": "eclipse"
},
{
"binary_version": "3.8.1-8",
"binary_name": "eclipse-jdt"
},
{
"binary_version": "3.8.1-8",
"binary_name": "eclipse-pde"
},
{
"binary_version": "3.8.1-8",
"binary_name": "eclipse-platform"
},
{
"binary_version": "3.8.1-8",
"binary_name": "eclipse-platform-data"
},
{
"binary_version": "3.8.1-8",
"binary_name": "eclipse-rcp"
},
{
"binary_version": "3.8.1-8",
"binary_name": "libequinox-osgi-java"
}
]
}
{
"binaries": [
{
"binary_version": "3.8.1-11",
"binary_name": "eclipse"
},
{
"binary_version": "3.8.1-11",
"binary_name": "eclipse-jdt"
},
{
"binary_version": "3.8.1-11",
"binary_name": "eclipse-pde"
},
{
"binary_version": "3.8.1-11",
"binary_name": "eclipse-platform"
},
{
"binary_version": "3.8.1-11",
"binary_name": "eclipse-platform-data"
},
{
"binary_version": "3.8.1-11",
"binary_name": "eclipse-rcp"
}
]
}