CVE Database
/

CVE-2008-3111

Back to search

CVE-2008-3111

Published: Jul 9, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allow context-dependent attackers to gain privileges via an untrusted application, as demonstrated by (a) an application that grants itself privileges to (1) read local files, (2) write to local files, or (3) execute local programs; and as demonstrated by (b) a long value associated with a java-vm-args attribute in a j2se tag in a JNLP file, which triggers a stack-based buffer overflow in the GetVMArgsOption function; aka CR 6557220.

VendorProductVersions

n/a

n/a

affected
n/a

References

APPLE-SA-2008-09-24
vendor-advisory
x_refsource_APPLE
31600
third-party-advisory
x_refsource_SECUNIA
SUSE-SA:2008:042
vendor-advisory
x_refsource_SUSE
32018
third-party-advisory
x_refsource_SECUNIA
GLSA-200911-02
vendor-advisory
x_refsource_GENTOO
32179
third-party-advisory
x_refsource_SECUNIA
ADV-2008-2740
vdb-entry
x_refsource_VUPEN
31320
third-party-advisory
x_refsource_SECUNIA
SUSE-SA:2008:043
vendor-advisory
x_refsource_SUSE
ADV-2008-2056
vdb-entry
x_refsource_VUPEN
238905
vendor-advisory
x_refsource_SUNALERT
31055
third-party-advisory
x_refsource_SECUNIA
32180
third-party-advisory
x_refsource_SECUNIA
31736
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:10541
vdb-entry
signature
x_refsource_OVAL
1020452
vdb-entry
x_refsource_SECTRACK
30148
vdb-entry
x_refsource_BID
31497
third-party-advisory
x_refsource_SECUNIA
SUSE-SA:2008:045
vendor-advisory
x_refsource_SUSE
RHSA-2008:0790
vendor-advisory
x_refsource_REDHAT
TA08-193A
third-party-advisory
x_refsource_CERT
37386
third-party-advisory
x_refsource_SECUNIA
RHSA-2008:0595
vendor-advisory
x_refsource_REDHAT
31010
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now