Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-5355

Опубликовано: 05 дек. 2008
Источник: ubuntu
Приоритет: low
CVSS2: 10

Описание

The "Java Update" feature for Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not verify the signature of the JRE that is downloaded, which allows remote attackers to execute arbitrary code via DNS man-in-the-middle attacks.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

6b14-0ubuntu4
gutsy

DNE

hardy

not-affected

code not compiled
intrepid

not-affected

code not compiled
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

not-affected

devel

not-affected

gutsy

not-affected

hardy

not-affected

intrepid

not-affected

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

gutsy

not-affected

hardy

not-affected

intrepid

not-affected

upstream

needs-triage

Показывать по

Ссылки на источники

10 Critical

CVSS2

Связанные уязвимости

redhat
около 17 лет назад

The "Java Update" feature for Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not verify the signature of the JRE that is downloaded, which allows remote attackers to execute arbitrary code via DNS man-in-the-middle attacks.

nvd
около 17 лет назад

The "Java Update" feature for Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not verify the signature of the JRE that is downloaded, which allows remote attackers to execute arbitrary code via DNS man-in-the-middle attacks.

debian
около 17 лет назад

The "Java Update" feature for Java Runtime Environment (JRE) for Sun J ...

github
больше 3 лет назад

The "Java Update" feature for Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not verify the signature of the JRE that is downloaded, which allows remote attackers to execute arbitrary code via DNS man-in-the-middle attacks.

10 Critical

CVSS2