PT-2008-6465 · Oracle+1 · Sun Jre+5

Publicado

2008-12-05

·

Atualizado

2017-09-29

·

CVE-2008-5341

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Java Web Start and Java Plug-in with Sun JDK and JRE versions prior to 6 Update 11 Java Web Start and Java Plug-in with Sun JDK and JRE 5.0 versions prior to 5.0 Update 17
Description The issue allows untrusted Java Web Start applications to obtain the pathname of the Java Web Start cache and the application username via unknown vectors.
Recommendations For Java Web Start and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier, update to version 6 Update 11 or later. For Java Web Start and Java Plug-in with Sun JDK and JRE 5.0 Update 16 and earlier, update to version 5.0 Update 17 or later.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-5341
HPSBUX02411
RHSA-2008:1018
RHSA-2008:1025
RHSA-2009:0016
RHSA-2009:0369

Produtos afetados

Hp-Ux
Java Platform
Java Plug-In
Java Web Start
Sun Jdk
Sun Jre