PT-2008-4532 · Oracle · Jre+3

Peter Csepely

·

Publicado

2008-07-09

·

Atualizado

2018-10-30

·

CVE-2008-3112

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: JDK and JRE 6 versions 6.0 through 6.0 Update 6 JDK and JRE 5.0 versions 5.0 through 5.0 Update 15 SDK and JRE 1.4.x versions 1.4.0 through 1.4.2 17
Description: The issue allows remote attackers to create arbitrary files. This can be achieved via the writeManifest method in the CacheEntry class or through an untrusted application.
Recommendations: For JDK and JRE 6 versions 6.0 through 6.0 Update 6, update to JDK and JRE 6 Update 7 or later. For JDK and JRE 5.0 versions 5.0 through 5.0 Update 15, update to JDK and JRE 5.0 Update 16 or later. For SDK and JRE 1.4.x versions 1.4.0 through 1.4.2 17, update to SDK and JRE 1.4.2 18 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-3112
RHSA-2008:0594
RHSA-2008:0595
RHSA-2008:0636
RHSA-2008:0638
RHSA-2008:0790
RHSA-2008:0906
RHSA-2008:0955

Produtos afetados

Jdk
Jre
Java Platform
Sdk