PT-2008-6476 · Oracle · Java Runtime Environment+1

Publicado

2008-12-05

·

Atualizado

2017-09-29

·

CVE-2008-5352

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Java Runtime Environment (JRE) versions 5.0 through 5.0 Update 16 Java Runtime Environment (JRE) versions 6 through 6 Update 10
Description The issue is related to an integer overflow in the JAR unpacking utility, which can be exploited by untrusted applications and applets to gain privileges. This can be achieved through a Pack200 compressed JAR file that triggers a heap-based buffer overflow.
Recommendations For Java Runtime Environment (JRE) versions 5.0 through 5.0 Update 16, update to a version later than 5.0 Update 16 to resolve the issue. For Java Runtime Environment (JRE) versions 6 through 6 Update 10, update to a version later than 6 Update 10 to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-5352
RHSA-2008:1018
RHSA-2008:1025
RHSA-2009:0015
RHSA-2009:0016
RHSA-2009:0466

Produtos afetados

Java Platform
Java Runtime Environment