PT-2008-6476 · Oracle · Java Runtime Environment+1

Published

2008-12-05

·

Updated

2017-09-29

·

CVE-2008-5352

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Java Runtime Environment (JRE) versions 5.0 through 5.0 Update 16 Java Runtime Environment (JRE) versions 6 through 6 Update 10
Description The issue is related to an integer overflow in the JAR unpacking utility, which can be exploited by untrusted applications and applets to gain privileges. This can be achieved through a Pack200 compressed JAR file that triggers a heap-based buffer overflow.
Recommendations For Java Runtime Environment (JRE) versions 5.0 through 5.0 Update 16, update to a version later than 5.0 Update 16 to resolve the issue. For Java Runtime Environment (JRE) versions 6 through 6 Update 10, update to a version later than 6 Update 10 to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-5352
RHSA-2008:1018
RHSA-2008:1025
RHSA-2009:0015
RHSA-2009:0016
RHSA-2009:0466

Affected Products

Java Platform
Java Runtime Environment