Description
ThreeTen Backport v1.6.8 was discovered to contain an integer overflow via the component org.threeten.bp.format.DateTimeFormatter::parse(CharSequence, ParsePosition). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.
References (3)
Core 3
Core References
Various Sources
https://github.com/ThreeTen/threetenbp
Various Sources
http://threeten.com
Various Sources
https://gist.github.com/LLM4IG/d2618f5f4e5ac37eb75cff5617e58b90
Scores
EPSS
0.0006
EPSS Percentile
17.8%
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
Status
published
Published
Apr 08, 2024
Tracked Since
Feb 18, 2026