Vulnerability Description
Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allows context-dependent attackers to gain privileges via unspecified vectors related to font processing.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sun | Jre | 1.3.1 |
| Sun | Jdk | 1.5.0 |
| Sun | Sdk | 1.3.1 |
Related Weaknesses (CWE)
References
- http://lists.apple.com/archives/security-announce//2008/Sep/msg00008.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00000.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00002.htmlMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=122331139823057&w=2Mailing ListThird Party Advisory
- http://secunia.com/advisories/31010Third Party Advisory
- http://secunia.com/advisories/31320Third Party Advisory
- http://secunia.com/advisories/31497Third Party Advisory
- http://secunia.com/advisories/31600Third Party Advisory
- http://secunia.com/advisories/31736Third Party Advisory
- http://secunia.com/advisories/32018Third Party Advisory
- http://secunia.com/advisories/32179Third Party Advisory
- http://secunia.com/advisories/32180Third Party Advisory
- http://secunia.com/advisories/33236Third Party Advisory
- http://secunia.com/advisories/33237Third Party Advisory
FAQ
What is CVE-2008-3108?
CVE-2008-3108 is a vulnerability with a CVSS score of 10.0 (HIGH). Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allows context-dependent attackers t...
How severe is CVE-2008-3108?
CVE-2008-3108 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-3108?
Check the references section above for vendor advisories and patch information. Affected products include: Sun Jre, Sun Jdk, Sun Sdk.