CVE-2025-1471 HIGH

CVE-2025-1471: Eclipse OMR: Buffer overflow vulnerability

Vendor Eclipse Foundation
Product Eclipse OMR
Weakness CWE-787
Published February 21, 2025
Last update February 25, 2025

CVSS base score

7.1/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

In Eclipse OMR versions 0.2.0 to 0.4.0, some of the z/OS atoe print functions use a constant length buffer for string conversion. If the input format string and arguments are larger than the buffer size then buffer overflow occurs. Beginning in version 0.5.0, the conversion buffers are sized correctly and checked appropriately to prevent buffer overflows.

Key dates

02Disclosure timeline

February 21, 2025 CVE published
February 25, 2025 Record updated