Vulnerability Description
Unspecified vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to obtain sensitive information (the cache location) via an untrusted application, aka CR 6704074.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sun | Jdk | <= 5.0 |
| Sun | Jre | <= 1.4.2_17 |
| Sun | Sdk | <= 1.4.2_17 |
Related Weaknesses (CWE)
References
- http://lists.apple.com/archives/security-announce//2008/Sep/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
- http://marc.info/?l=bugtraq&m=122331139823057&w=2
- http://rhn.redhat.com/errata/RHSA-2008-0955.html
- http://secunia.com/advisories/31010Vendor Advisory
- http://secunia.com/advisories/31055
- http://secunia.com/advisories/31320
- http://secunia.com/advisories/31497
- http://secunia.com/advisories/31600
- http://secunia.com/advisories/31736
- http://secunia.com/advisories/32018
FAQ
What is CVE-2008-3114?
CVE-2008-3114 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Unspecified vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to obtain s...
How severe is CVE-2008-3114?
CVE-2008-3114 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-3114?
Check the references section above for vendor advisories and patch information. Affected products include: Sun Jdk, Sun Jre, Sun Sdk.