PT-2008-6476 · Oracle · Java Runtime Environment+1
Published
2008-12-05
·
Updated
2017-09-29
·
CVE-2008-5352
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Java Runtime Environment (JRE) versions 5.0 through 5.0 Update 16
Java Runtime Environment (JRE) versions 6 through 6 Update 10
Description
The issue is related to an integer overflow in the JAR unpacking utility, which can be exploited by untrusted applications and applets to gain privileges. This can be achieved through a Pack200 compressed JAR file that triggers a heap-based buffer overflow.
Recommendations
For Java Runtime Environment (JRE) versions 5.0 through 5.0 Update 16, update to a version later than 5.0 Update 16 to resolve the issue.
For Java Runtime Environment (JRE) versions 6 through 6 Update 10, update to a version later than 6 Update 10 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Java Platform
Java Runtime Environment