CVE-2008-3112

EUVD-2008-3102
Directory traversal vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create arbitrary files via the writeManifest method in the CacheEntry class, aka CR 6703909.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
Affected Products (NVD)
VendorProductVersion
sunjdk
𝑥
≤ 5.0
sunjdk
𝑥
≤ 6
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjdk
5.0
sunjre
𝑥
≤ 1.4.2_17
sunjre
𝑥
≤ 5.0
sunjre
𝑥
≤ 6
sunjre
1.4.2
sunjre
1.4.2_01:_01
sunjre
1.4.2_02:_02
sunjre
1.4.2_03:_03
sunjre
1.4.2_04:_04
sunjre
1.4.2_05:_05
sunjre
1.4.2_06:_06
sunjre
1.4.2_07:_07
sunjre
1.4.2_8:_8
sunjre
1.4.2_9:_9
sunjre
1.4.2_10:_10
sunjre
1.4.2_11:_11
sunjre
1.4.2_12:_12
sunjre
1.4.2_13:_13
sunjre
1.4.2_14:_14
sunjre
1.4.2_15:_15
sunjre
1.4.2_16:_16
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunjre
5.0
sunsdk
1.4.2
sunsdk
1.4.2_01:_01
sunsdk
1.4.2_02:_02
sunsdk
1.4.2_03:_03
sunsdk
1.4.2_04:_04
sunsdk
1.4.2_05:_05
sunsdk
1.4.2_06:_06
sunsdk
1.4.2_07:_07
sunsdk
1.4.2_08:_08
sunsdk
1.4.2_09:_09
sunsdk
1.4.2_10:_10
sunsdk
1.4.2_11:_11
sunsdk
1.4.2_12:_12
sunsdk
1.4.2_13:_13
sunsdk
1.4.2_14:_14
sunsdk
1.4.2_15:_15
sunsdk
1.4.2_16:_16
sunsdk
1.4.2_17:_17
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sun-java5
dapper
ignored
feisty
ignored
gutsy
ignored
hardy
Fixed 1.5.0-22-0ubuntu0.8.04
released
intrepid
not-affected
jaunty
not-affected
karmic
dne
sun-java6
dapper
dne
feisty
ignored
gutsy
ignored
hardy
Fixed 6-17-0ubuntu1.8.04
released
intrepid
not-affected
jaunty
not-affected
karmic
not-affected
Common Weakness Enumeration
References