CVE Vulnerabilities

CVE-2008-5352

Published: Dec 05, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Integer overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack.dll) in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted applications and applets to gain privileges via a Pack200 compressed JAR file that triggers a heap-based buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
JdkSun*5.0 (including)
JdkSun*6 (including)
JdkSun5.0-update_1 (including)5.0-update_1 (including)
JdkSun5.0-update_10 (including)5.0-update_10 (including)
JdkSun5.0-update_11 (including)5.0-update_11 (including)
JdkSun5.0-update_12 (including)5.0-update_12 (including)
JdkSun5.0-update_13 (including)5.0-update_13 (including)
JdkSun5.0-update_14 (including)5.0-update_14 (including)
JdkSun5.0-update_15 (including)5.0-update_15 (including)
JdkSun5.0-update_2 (including)5.0-update_2 (including)
JdkSun5.0-update_3 (including)5.0-update_3 (including)
JdkSun6 (including)6 (including)
JdkSun6-update_1 (including)6-update_1 (including)
JdkSun6-update_2 (including)6-update_2 (including)
JdkSun6-update_3 (including)6-update_3 (including)
JdkSun6-update_4 (including)6-update_4 (including)
JdkSun6-update_5 (including)6-update_5 (including)
JdkSun6-update_6 (including)6-update_6 (including)
JdkSun6-update_7 (including)6-update_7 (including)
JdkSun6-update_8 (including)6-update_8 (including)
JreSun*5.0 (including)
JreSun*6 (including)
JreSun5.0 (including)5.0 (including)
JreSun5.0-update_1 (including)5.0-update_1 (including)
JreSun5.0-update_10 (including)5.0-update_10 (including)
JreSun5.0-update_11 (including)5.0-update_11 (including)
JreSun5.0-update_12 (including)5.0-update_12 (including)
JreSun5.0-update_13 (including)5.0-update_13 (including)
JreSun5.0-update_14 (including)5.0-update_14 (including)
JreSun5.0-update_15 (including)5.0-update_15 (including)
JreSun5.0-update_2 (including)5.0-update_2 (including)
JreSun6 (including)6 (including)
JreSun6-update_1 (including)6-update_1 (including)
JreSun6-update_2 (including)6-update_2 (including)
JreSun6-update_3 (including)6-update_3 (including)
JreSun6-update_4 (including)6-update_4 (including)
JreSun6-update_5 (including)6-update_5 (including)
JreSun6-update_6 (including)6-update_6 (including)
JreSun6-update_7 (including)6-update_7 (including)
JreSun6-update_8 (including)6-update_8 (including)
Extras for RHEL 4RedHatjava-1.6.0-sun-1:1.6.0.11-1jpp.1.el4*
Extras for RHEL 4RedHatjava-1.5.0-sun-0:1.5.0.17-1jpp.2.el4*
Extras for RHEL 4RedHatjava-1.6.0-ibm-1:1.6.0.3-1jpp.3.el4*
Extras for RHEL 4RedHatjava-1.5.0-ibm-1:1.5.0.9-1jpp.4.el4*
Red Hat Network Satellite Server v 5.2RedHatjava-1.5.0-ibm-1:1.5.0.9-1jpp.4.el4*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.6.0-sun-1:1.6.0.11-1jpp.1.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.5.0-sun-0:1.5.0.17-1jpp.2.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.6.0-ibm-1:1.6.0.3-1jpp.1.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.5.0-ibm-1:1.5.0.9-1jpp.2.el5*
Openjdk-6Ubuntuhardy*
Openjdk-6Ubuntuintrepid*
Sun-java5Ubuntudapper*
Sun-java5Ubuntugutsy*
Sun-java5Ubuntuhardy*
Sun-java5Ubuntuintrepid*
Sun-java5Ubuntujaunty*
Sun-java6Ubuntudevel*
Sun-java6Ubuntugutsy*
Sun-java6Ubuntuhardy*
Sun-java6Ubuntuintrepid*
Sun-java6Ubuntujaunty*
Sun-java6Ubuntukarmic*

References