CVE-2008-3111

EUVD-2008-3101
Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allow context-dependent attackers to gain privileges via an untrusted application, as demonstrated by (a) an application that grants itself privileges to (1) read local files, (2) write to local files, or (3) execute local programs; and as demonstrated by (b) a long value associated with a java-vm-args attribute in a j2se tag in a JNLP file, which triggers a stack-based buffer overflow in the GetVMArgsOption function; aka CR 6557220.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
Affected Products (NVD)
VendorProductVersion
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjre
1.4
sunjre
1.4.2_01:_01
sunjre
1.4.2_02:_02
sunjre
1.4.2_03:_03
sunjre
1.4.2_04:_04
sunjre
1.4.2_05:_05
sunjre
1.4.2_06:_06
sunjre
1.4.2_07:_07
sunjre
1.4.2_8:_8
sunjre
1.4.2_9:_9
sunjre
1.4.2_10:_10
sunjre
1.4.2_11:_11
sunjre
1.4.2_12:_12
sunjre
1.4.2_13:_13
sunjre
1.4.2_14:_14
sunjre
1.4.2_15:_15
sunjre
1.4.2_16:_16
sunjre
1.4.2_17:_17
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunsdk
1.4
sunsdk
1.4.2
sunsdk
1.4.2_01:_01
sunsdk
1.4.2_02:_02
sunsdk
1.4.2_03:_03
sunsdk
1.4.2_04:_04
sunsdk
1.4.2_05:_05
sunsdk
1.4.2_06:_06
sunsdk
1.4.2_07:_07
sunsdk
1.4.2_08:_08
sunsdk
1.4.2_09:_09
sunsdk
1.4.2_10:_10
sunsdk
1.4.2_11:_11
sunsdk
1.4.2_12:_12
sunsdk
1.4.2_13:_13
sunsdk
1.4.2_14:_14
sunsdk
1.4.2_15:_15
sunsdk
1.4.2_16:_16
sunsdk
1.4.2_17:_17
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sun-java5
dapper
ignored
feisty
ignored
gutsy
ignored
hardy
Fixed 1.5.0-22-0ubuntu0.8.04
released
intrepid
not-affected
jaunty
not-affected
karmic
dne
sun-java6
dapper
dne
feisty
ignored
gutsy
ignored
hardy
Fixed 6-17-0ubuntu1.8.04
released
intrepid
not-affected
jaunty
not-affected
karmic
not-affected
References