Vulnerability Description
Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allow context-dependent attackers to gain privileges via an untrusted application, as demonstrated by (a) an application that grants itself privileges to (1) read local files, (2) write to local files, or (3) execute local programs; and as demonstrated by (b) a long value associated with a java-vm-args attribute in a j2se tag in a JNLP file, which triggers a stack-based buffer overflow in the GetVMArgsOption function; aka CR 6557220.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sun | Jdk | 5.0 |
| Sun | Jre | 1.4 |
| Sun | Sdk | 1.4 |
Related Weaknesses (CWE)
References
- http://lists.apple.com/archives/security-announce//2008/Sep/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00002.html
- http://marc.info/?l=bugtraq&m=122331139823057&w=2
- http://secunia.com/advisories/31010Vendor Advisory
- http://secunia.com/advisories/31055Vendor Advisory
- http://secunia.com/advisories/31320Vendor Advisory
- http://secunia.com/advisories/31497Vendor Advisory
- http://secunia.com/advisories/31600Vendor Advisory
- http://secunia.com/advisories/31736
- http://secunia.com/advisories/32018Vendor Advisory
- http://secunia.com/advisories/32179Vendor Advisory
- http://secunia.com/advisories/32180Vendor Advisory
- http://secunia.com/advisories/37386Vendor Advisory
FAQ
What is CVE-2008-3111?
CVE-2008-3111 is a vulnerability with a CVSS score of 10.0 (HIGH). Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allow context-dependent attackers to gain priv...
How severe is CVE-2008-3111?
CVE-2008-3111 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-3111?
Check the references section above for vendor advisories and patch information. Affected products include: Sun Jdk, Sun Jre, Sun Sdk.