CVE-2008-1189
published 2008-03-06CVE-2008-1189: Buffer overflow in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote…
PriorityP339medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
7.19%
93.6th percentile
Buffer overflow in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to execute arbitrary code via unknown vectors, a different issue than CVE-2008-1188, aka the "third" issue.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | sdk | — | — |
| sun | sdk | — | — |
| sun | sdk | — | — |
| sun | sdk | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hppm-r8m5-wmwp: Buffer overflow in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2008-1189 [CRITICAL] CWE-119 GHSA-hppm-r8m5-wmwp: Buffer overflow in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5
Buffer overflow in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to execute arbitrary code via unknown vectors, a different issue than CVE-2008-1188, aka the "third" issue.
GHSA
GHSA-x67m-cmr9-2j82: Multiple buffer overflows in the useEncodingDecl function in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, and 5
ghsa_unreviewed·2022-05-01·CVSS 6.8
CVE-2008-1188 [MEDIUM] CWE-119 GHSA-x67m-cmr9-2j82: Multiple buffer overflows in the useEncodingDecl function in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, and 5
Multiple buffer overflows in the useEncodingDecl function in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allow remote attackers to execute arbitrary code via a JNLP file with (1) a long key name in the xml header or (2) a long charset value, different issues than CVE-2008-1189, aka "The first two issues."
Red Hat
dbus: invalid fix for CVE-2008-3834
vendor_redhat·2009-04-16·CVSS 2.1
CVE-2009-1189 [LOW] dbus: invalid fix for CVE-2008-3834
dbus: invalid fix for CVE-2008-3834
The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834.
Red Hat
Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)
vendor_redhat·2008-03-06·CVSS 9.3
CVE-2008-1188 [CRITICAL] Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)
Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)
Multiple buffer overflows in the useEncodingDecl function in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allow remote attackers to execute arbitrary code via a JNLP file with (1) a long key name in the xml header or (2) a long charset value, different issues than CVE-2008-1189, aka "The first two issues."
Red Hat
Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)
vendor_redhat·2008-03-06·CVSS 9.3
CVE-2008-1189 [CRITICAL] Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)
Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)
Buffer overflow in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to execute arbitrary code via unknown vectors, a different issue than CVE-2008-1188, aka the "third" issue.
Red Hat
Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)
vendor_redhat·2008-03-06·CVSS 6.8
CVE-2008-1190 [MEDIUM] Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)
Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)
Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application, a different issue than CVE-2008-1191, aka the "fourth" issue.
No detection rules found.
Bugzilla
CVE-2009-1189 dbus: invalid fix for CVE-2008-3834
bugzilla·2009-04-20·CVSS 2.1
CVE-2009-1189 [LOW] CVE-2009-1189 dbus: invalid fix for CVE-2008-3834
CVE-2009-1189 dbus: invalid fix for CVE-2008-3834
It was found that the patch to fix CVE-2008-3834 in dbus was incorrect and as a
result the flaw was never properly fixed (remote denial of service
vulnerability). This issue has been assigned CVE-2009-1189.
The upstream bug report is here:
https://bugs.freedesktop.org/show_bug.cgi?id=17803
Our bug report for CVE-2008-3834 is bug #464674 .
Discussion:
The upstream fix is here:
https://bugs.freedesktop.org/attachment.cgi?id=24436
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0018 https://rhn.redhat.com/errata/RHSA-2010-0018.html
Bugzilla
CVE-2008-1188 Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)
bugzilla·2008-03-06·CVSS 9.3
CVE-2008-1188 [CRITICAL] CVE-2008-1188 Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)
CVE-2008-1188 Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)
Three buffer overflow security vulnerabilities in Java Web Start may
independently allow an untrusted Java Web Start application that is downloaded
from a website to elevate its privileges. For example, an untrusted Java Web
Start application may grant itself permissions to read and write local files or
execute local applications that are accessible to the user running the untrusted
application.
A vulnerability in Java Web Start may allow an untrusted Java Web Start
application to elevate its privileges. For example, an application may grant
itself permissions to read and write local files or execute local applications
that are accessible to the user running the untrusted application.
http://lists.apple.com/archives/security-announce//2008/Sep/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.htmlhttp://secunia.com/advisories/29239http://secunia.com/advisories/29273http://secunia.com/advisories/29498http://secunia.com/advisories/29582http://secunia.com/advisories/29858http://secunia.com/advisories/29897http://secunia.com/advisories/30676http://secunia.com/advisories/30780http://secunia.com/advisories/31497http://secunia.com/advisories/32018http://security.gentoo.org/glsa/glsa-200804-28.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-233323-1http://support.apple.com/kb/HT3178http://support.apple.com/kb/HT3179http://www.gentoo.org/security/en/glsa/glsa-200804-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200806-11.xmlhttp://www.redhat.com/support/errata/RHSA-2008-0186.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0210.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0267.htmlhttp://www.securitytracker.com/id?1019549http://www.us-cert.gov/cas/techalerts/TA08-066A.htmlhttp://www.vmware.com/security/advisories/VMSA-2008-0010.htmlhttp://www.vupen.com/english/advisories/2008/0770/referenceshttp://www.vupen.com/english/advisories/2008/1856/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41029https://exchange.xforce.ibmcloud.com/vulnerabilities/41133https://exchange.xforce.ibmcloud.com/vulnerabilities/41135https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9582http://lists.apple.com/archives/security-announce//2008/Sep/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.htmlhttp://secunia.com/advisories/29239http://secunia.com/advisories/29273http://secunia.com/advisories/29498http://secunia.com/advisories/29582http://secunia.com/advisories/29858http://secunia.com/advisories/29897http://secunia.com/advisories/30676http://secunia.com/advisories/30780http://secunia.com/advisories/31497http://secunia.com/advisories/32018http://security.gentoo.org/glsa/glsa-200804-28.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-233323-1http://support.apple.com/kb/HT3178http://support.apple.com/kb/HT3179http://www.gentoo.org/security/en/glsa/glsa-200804-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200806-11.xmlhttp://www.redhat.com/support/errata/RHSA-2008-0186.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0210.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0267.htmlhttp://www.securitytracker.com/id?1019549http://www.us-cert.gov/cas/techalerts/TA08-066A.htmlhttp://www.vmware.com/security/advisories/VMSA-2008-0010.htmlhttp://www.vupen.com/english/advisories/2008/0770/referenceshttp://www.vupen.com/english/advisories/2008/1856/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41029https://exchange.xforce.ibmcloud.com/vulnerabilities/41133https://exchange.xforce.ibmcloud.com/vulnerabilities/41135https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9582
2008-03-06
Published