CVE-2008-3111

Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allow context-dependent attackers to gain privileges via an untrusted application, as demonstrated by (a) an application that grants itself privileges to (1) read local files, (2) write to local files, or (3) execute local programs; and as demonstrated by (b) a long value associated with a java-vm-args attribute in a j2se tag in a JNLP file, which triggers a stack-based buffer overflow in the GetVMArgsOption function; aka CR 6557220.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
VendorProductVersion
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjre
1.4
sunjre
1.4.2_01:_01
sunjre
1.4.2_02:_02
sunjre
1.4.2_03:_03
sunjre
1.4.2_04:_04
sunjre
1.4.2_05:_05
sunjre
1.4.2_06:_06
sunjre
1.4.2_07:_07
sunjre
1.4.2_8:_8
sunjre
1.4.2_9:_9
sunjre
1.4.2_10:_10
sunjre
1.4.2_11:_11
sunjre
1.4.2_12:_12
sunjre
1.4.2_13:_13
sunjre
1.4.2_14:_14
sunjre
1.4.2_15:_15
sunjre
1.4.2_16:_16
sunjre
1.4.2_17:_17
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunsdk
1.4
sunsdk
1.4.2
sunsdk
1.4.2_01:_01
sunsdk
1.4.2_02:_02
sunsdk
1.4.2_03:_03
sunsdk
1.4.2_04:_04
sunsdk
1.4.2_05:_05
sunsdk
1.4.2_06:_06
sunsdk
1.4.2_07:_07
sunsdk
1.4.2_08:_08
sunsdk
1.4.2_09:_09
sunsdk
1.4.2_10:_10
sunsdk
1.4.2_11:_11
sunsdk
1.4.2_12:_12
sunsdk
1.4.2_13:_13
sunsdk
1.4.2_14:_14
sunsdk
1.4.2_15:_15
sunsdk
1.4.2_16:_16
sunsdk
1.4.2_17:_17
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sun-java5
karmic
dne
jaunty
not-affected
intrepid
not-affected
hardy
Fixed 1.5.0-22-0ubuntu0.8.04
released
gutsy
ignored
feisty
ignored
dapper
ignored
sun-java6
karmic
not-affected
jaunty
not-affected
intrepid
not-affected
hardy
Fixed 6-17-0ubuntu1.8.04
released
gutsy
ignored
feisty
ignored
dapper
dne
References