CVE-2008-1191
published 2008-03-06CVE-2008-1191: Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier allows remote attackers to create arbitrary files via an untrusted…
PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.65%
88.3th percentile
Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier allows remote attackers to create arbitrary files via an untrusted application, a different issue than CVE-2008-1190, aka "The fifth issue."
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 6_update_4 | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | <= 6_update_4 | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | sdk | — | — |
| sun | sdk | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Untrusted Java Web Start arbitrary file creation
vendor_redhat·2008-03-06·CVSS 9.3
CVE-2008-1191 [CRITICAL] Untrusted Java Web Start arbitrary file creation
Untrusted Java Web Start arbitrary file creation
Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier allows remote attackers to create arbitrary files via an untrusted application, a different issue than CVE-2008-1190, aka "The fifth issue."
Red Hat
Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)
vendor_redhat·2008-03-06·CVSS 6.8
CVE-2008-1190 [MEDIUM] Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)
Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)
Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application, a different issue than CVE-2008-1191, aka the "fourth" issue.
GHSA
GHSA-rp3q-rw9w-295j: Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier allows remote attackers to create arbitrary files via an untrust
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2008-1191 [CRITICAL] GHSA-rp3q-rw9w-295j: Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier allows remote attackers to create arbitrary files via an untrust
Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier allows remote attackers to create arbitrary files via an untrusted application, a different issue than CVE-2008-1190, aka "The fifth issue."
GHSA
GHSA-m6g6-6pj7-xcc2: Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5
ghsa_unreviewed·2022-05-01·CVSS 6.8
CVE-2008-1190 [MEDIUM] GHSA-m6g6-6pj7-xcc2: Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5
Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application, a different issue than CVE-2008-1191, aka the "fourth" issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-1191 httpd mod_proxy_ajp information disclosure
bugzilla·2009-04-21·CVSS 2.6
CVE-2009-1191 [LOW] CVE-2009-1191 httpd mod_proxy_ajp information disclosure
CVE-2009-1191 httpd mod_proxy_ajp information disclosure
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-1191 to the following vulnerability:
mod_proxy_ajp in Apache httpd 2.2.11 allows remote attackers to obtain sensitive information via an arbitrary request from a HTTP client, in opportunistic circumstances involving a request from a different client that included a Content-Length header but no POST data.
This is similar to the issue CVE-2008-5519 in mod_jk
Prior to httpd 2.2.11 this was not an issue. It was an issue
due to http://svn.apache.org/viewvc?view=rev&revision=711779
Patch will be applied to 2.2.12:
http://www.apache.org/dist/httpd/patches/apply_to_2.2.11/
Discussion:
The patch is available for download from the following location:
https://support.re
Bugzilla
CVE-2008-1191 Untrusted Java Web Start arbitrary file creation
bugzilla·2008-04-30·CVSS 9.3
CVE-2008-1191 [CRITICAL] CVE-2008-1191 Untrusted Java Web Start arbitrary file creation
CVE-2008-1191 Untrusted Java Web Start arbitrary file creation
From http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1191:
Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and
earlier allows remote attackers to create arbitrary files via an untrusted
application, a different issue than CVE-2008-1190, aka "The fifth issue."
Discussion:
This was corrected via:
RHEL Supplementary version 5 (RHSA-2008:0267)
Bugzilla
CVE-2008-1188 Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)
bugzilla·2008-03-06·CVSS 9.3
CVE-2008-1188 [CRITICAL] CVE-2008-1188 Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)
CVE-2008-1188 Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)
Three buffer overflow security vulnerabilities in Java Web Start may
independently allow an untrusted Java Web Start application that is downloaded
from a website to elevate its privileges. For example, an untrusted Java Web
Start application may grant itself permissions to read and write local files or
execute local applications that are accessible to the user running the untrusted
application.
A vulnerability in Java Web Start may allow an untrusted Java Web Start
application to elevate its privileges. For example, an application may grant
itself permissions to read and write local files or execute local applications
that are accessible to the user running the untrusted application.
http://lists.apple.com/archives/security-announce//2008/Sep/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00000.htmlhttp://secunia.com/advisories/29239http://secunia.com/advisories/29273http://secunia.com/advisories/29582http://secunia.com/advisories/29858http://secunia.com/advisories/30676http://secunia.com/advisories/30780http://secunia.com/advisories/32018http://security.gentoo.org/glsa/glsa-200804-28.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-233323-1http://support.apple.com/kb/HT3178http://support.apple.com/kb/HT3179http://www.gentoo.org/security/en/glsa/glsa-200804-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200806-11.xmlhttp://www.redhat.com/support/errata/RHSA-2008-0186.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0267.htmlhttp://www.securitytracker.com/id?1019549http://www.us-cert.gov/cas/techalerts/TA08-066A.htmlhttp://www.vmware.com/security/advisories/VMSA-2008-0010.htmlhttp://www.vupen.com/english/advisories/2008/0770/referenceshttp://www.vupen.com/english/advisories/2008/1856/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41029https://exchange.xforce.ibmcloud.com/vulnerabilities/41136https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10167http://lists.apple.com/archives/security-announce//2008/Sep/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00000.htmlhttp://secunia.com/advisories/29239http://secunia.com/advisories/29273http://secunia.com/advisories/29582http://secunia.com/advisories/29858http://secunia.com/advisories/30676http://secunia.com/advisories/30780http://secunia.com/advisories/32018http://security.gentoo.org/glsa/glsa-200804-28.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-233323-1http://support.apple.com/kb/HT3178http://support.apple.com/kb/HT3179http://www.gentoo.org/security/en/glsa/glsa-200804-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200806-11.xmlhttp://www.redhat.com/support/errata/RHSA-2008-0186.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0267.htmlhttp://www.securitytracker.com/id?1019549http://www.us-cert.gov/cas/techalerts/TA08-066A.htmlhttp://www.vmware.com/security/advisories/VMSA-2008-0010.htmlhttp://www.vupen.com/english/advisories/2008/0770/referenceshttp://www.vupen.com/english/advisories/2008/1856/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41029https://exchange.xforce.ibmcloud.com/vulnerabilities/41136https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10167
2008-03-06
Published