CVE-2008-3440
01.08.2008, 14:41
Sun Java 1.6.0_03 and earlier versions, and possibly later versions, does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
Vendor | Product | Version |
---|---|---|
sun | java | 𝑥 ≤ 1.6.0 |
sun | java | 1.6.0 |
sun | java | 1.6.0:01 |
sun | java | 1.6.0:02 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References