PT-2008-6476 · Oracle · Java Runtime Environment+1
Publicado
2008-12-05
·
Atualizado
2017-09-29
·
CVE-2008-5352
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Java Runtime Environment (JRE) versions 5.0 through 5.0 Update 16
Java Runtime Environment (JRE) versions 6 through 6 Update 10
Description
The issue is related to an integer overflow in the JAR unpacking utility, which can be exploited by untrusted applications and applets to gain privileges. This can be achieved through a Pack200 compressed JAR file that triggers a heap-based buffer overflow.
Recommendations
For Java Runtime Environment (JRE) versions 5.0 through 5.0 Update 16, update to a version later than 5.0 Update 16 to resolve the issue.
For Java Runtime Environment (JRE) versions 6 through 6 Update 10, update to a version later than 6 Update 10 to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Java Platform
Java Runtime Environment