Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-5353

Опубликовано: 05 дек. 2008
Источник: ubuntu
Приоритет: medium
EPSS Критический
CVSS2: 10

Описание

The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote attackers to run untrusted applets and applications in a privileged context, as demonstrated by "deserializing Calendar objects".

РелизСтатусПримечание
dapper

DNE

devel

not-affected

6b14-0ubuntu4
gutsy

DNE

hardy

released

6b11-2ubuntu2.1
intrepid

released

6b12-0ubuntu6.1
jaunty

not-affected

6b14-0ubuntu4
karmic

not-affected

6b14-0ubuntu4
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

gutsy

ignored

end of life, was needs-triage
hardy

released

1.5.0-22-0ubuntu0.8.04
intrepid

released

1.5.0-19-0ubuntu0.8.10
jaunty

released

1.5.0-19-0ubuntu0.9.04
karmic

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

released

6.19-0ubuntu1
gutsy

ignored

end of life, was needs-triage
hardy

released

6-17-0ubuntu1.8.04
intrepid

released

6-14-0ubuntu1.8.10
jaunty

released

6-16-0ubuntu1.9.04
karmic

released

6-15-1
upstream

needs-triage

Показывать по

EPSS

Процентиль: 100%
0.90124
Критический

10 Critical

CVSS2

Связанные уязвимости

redhat
около 17 лет назад

The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote attackers to run untrusted applets and applications in a privileged context, as demonstrated by "deserializing Calendar objects".

nvd
около 17 лет назад

The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote attackers to run untrusted applets and applications in a privileged context, as demonstrated by "deserializing Calendar objects".

debian
около 17 лет назад

The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and ...

github
больше 3 лет назад

The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote attackers to run untrusted applets and applications in a privileged context, as demonstrated by "deserializing Calendar objects".

EPSS

Процентиль: 100%
0.90124
Критический

10 Critical

CVSS2

Уязвимость CVE-2008-5353