Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2008-5356

Опубликовано: 04 дек. 2008
Источник: redhat
CVSS2: 7.5
EPSS Низкий

Описание

Heap-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 3java-1.4.2-ibmWill not fix
Red Hat Enterprise Linux 4java-1.4.2-ibmWill not fix
Red Hat Enterprise Linux 5java-1.4.2-ibmWill not fix
Red Hat Enterprise Linux 5java-1.4.2-ibm-sapWill not fix
Red Hat Enterprise Linux 5java-1.6.0-openjdkNot affected
Red Hat Enterprise Linux 6java-1.4.2-ibm-sapWill not fix
Red Hat Enterprise Linux 6java-1.5.0-ibmNot affected
Red Hat Enterprise Linux 6java-1.6.0-ibmNot affected
Red Hat Enterprise Linux 6java-1.6.0-openjdkNot affected
Red Hat Enterprise Linux 6java-1.6.0-sunNot affected

Показывать по

Дополнительная информация

Статус:

Critical
https://bugzilla.redhat.com/show_bug.cgi?id=472218OpenJDK Font processing vulnerability (6733336)

EPSS

Процентиль: 92%
0.07682
Низкий

7.5 High

CVSS2

Связанные уязвимости

ubuntu
около 17 лет назад

Heap-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file.

nvd
около 17 лет назад

Heap-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file.

debian
около 17 лет назад

Heap-based buffer overflow in Java Runtime Environment (JRE) for Sun J ...

github
больше 3 лет назад

Heap-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file.

EPSS

Процентиль: 92%
0.07682
Низкий

7.5 High

CVSS2