Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-3111

Опубликовано: 09 июл. 2008
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 10

Описание

Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allow context-dependent attackers to gain privileges via an untrusted application, as demonstrated by (a) an application that grants itself privileges to (1) read local files, (2) write to local files, or (3) execute local programs; and as demonstrated by (b) a long value associated with a java-vm-args attribute in a j2se tag in a JNLP file, which triggers a stack-based buffer overflow in the GetVMArgsOption function; aka CR 6557220.

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

feisty

ignored

end of life, was needs-triage
gutsy

ignored

end of life, was needs-triage
hardy

released

1.5.0-22-0ubuntu0.8.04
intrepid

not-affected

1.5.0-16-2ubuntu1
jaunty

not-affected

1.5.0-16-2ubuntu1
karmic

DNE

upstream

released

1.5.0-16-1

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

6-07-3ubuntu1
feisty

ignored

end of life, was needs-triage
gutsy

ignored

end of life, was needs-triage
hardy

released

6-17-0ubuntu1.8.04
intrepid

not-affected

6-07-3ubuntu1
jaunty

not-affected

6-07-3ubuntu1
karmic

not-affected

6-07-3ubuntu1
upstream

released

6-04-1

Показывать по

Ссылки на источники

EPSS

Процентиль: 94%
0.13359
Средний

10 Critical

CVSS2

Связанные уязвимости

redhat
больше 17 лет назад

Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allow context-dependent attackers to gain privileges via an untrusted application, as demonstrated by (a) an application that grants itself privileges to (1) read local files, (2) write to local files, or (3) execute local programs; and as demonstrated by (b) a long value associated with a java-vm-args attribute in a j2se tag in a JNLP file, which triggers a stack-based buffer overflow in the GetVMArgsOption function; aka CR 6557220.

nvd
больше 17 лет назад

Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allow context-dependent attackers to gain privileges via an untrusted application, as demonstrated by (a) an application that grants itself privileges to (1) read local files, (2) write to local files, or (3) execute local programs; and as demonstrated by (b) a long value associated with a java-vm-args attribute in a j2se tag in a JNLP file, which triggers a stack-based buffer overflow in the GetVMArgsOption function; aka CR 6557220.

debian
больше 17 лет назад

Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 befor ...

github
больше 3 лет назад

Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allow context-dependent attackers to gain privileges via an untrusted application, as demonstrated by (a) an application that grants itself privileges to (1) read local files, (2) write to local files, or (3) execute local programs; and as demonstrated by (b) a long value associated with a java-vm-args attribute in a j2se tag in a JNLP file, which triggers a stack-based buffer overflow in the GetVMArgsOption function; aka CR 6557220.

EPSS

Процентиль: 94%
0.13359
Средний

10 Critical

CVSS2