CVE-2008-3108
published 2008-07-09CVE-2008-3108: Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before…
PriorityP345critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.61%
90.6th percentile
Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allows context-dependent attackers to gain privileges via unspecified vectors related to font processing.
Affected
95 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8wxg-8gj7-8j93: Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5
ghsa_unreviewed·2022-05-01
CVE-2008-3108 [HIGH] CWE-119 GHSA-8wxg-8gj7-8j93: Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5
Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allows context-dependent attackers to gain privileges via unspecified vectors related to font processing.
VMware
VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issues
vendor_vmware·2008-10-03·CVSS 6.8
CVE-2008-3103 [MEDIUM] VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issues
VMSA-2008-0016: VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issues
a. Privilege escalation on 64-bit guest operating systems VMware products emulate hardware functions, like CPU, Memory, and IO. A flaw in VMware's CPU hardware emulation could allow the virtual CPU to jump to an incorrect memory address. Exploitation of this issue on the guest operating system does not lead to a compromise of the host system but could lead to a privilege escalation on guest operating system. An attacker would need to have a user account on the guest operating system. Affected 64-bit Windows and 64-bit FreeBSD guest operating systems and possibly other 64-bit operating systems. The issue does not affect the 64-bit versions of Linux guest operating sy
Red Hat
Security Vulnerability with JRE fonts processing may allow Elevation of Privileges (6450319)
vendor_redhat·2008-07-08·CVSS 10.0
CVE-2008-3108 [CRITICAL] Security Vulnerability with JRE fonts processing may allow Elevation of Privileges (6450319)
Security Vulnerability with JRE fonts processing may allow Elevation of Privileges (6450319)
Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allows context-dependent attackers to gain privileges via unspecified vectors related to font processing.
VMware
Updated service console patches.
vendor_vmware·2008-01-07·CVSS 1.2
CVE-2007-3108 [LOW] Updated service console patches.
VMSA-2008-0001: Updated service console patches.
Updated service console patches. VMware Security Advisory VMware Security Advisory Advisory ID: VMware Security Advisory Synopsis: Updated service console patches. VMware Security Advisory Issue date: VMware Security Advisory Updated on:
CVEs: CVE-2007-3108, CVE-2007-4572, CVE-2007-5116, CVE-2007-5135, CVE-2007-5191, CVE-2007-5360, CVE-2007-5398
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-5101 OptiPNG: Buffer overflow in BMP image handling reader
bugzilla·2008-11-12·CVSS 9.3
CVE-2008-5101 [CRITICAL] CVE-2008-5101 OptiPNG: Buffer overflow in BMP image handling reader
CVE-2008-5101 OptiPNG: Buffer overflow in BMP image handling reader
A buffer overflow flaw has been found in the OptiPNG -- PNG image optimizer.
This flaw is caused due to an boundary error in the BMP image reader,
responsible for handling BMP images. Local unprivileged user could
use this flaw to execure arbitary code via providing a specially crafted
BMP image file to the optimizer.
Affected OptinPNG versions: all prior to 0.6.2
References:
http://sourceforge.net/project/shownotes.php?release_id=639631&group_id=151404
http://secunia.com/Advisories/32651/
http://www.frsirt.com/english/advisories/2008/3108/references
http://optipng.sourceforge.net/
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=505399
Proposed solution:
Upgrade to OptiPNG 0.6.2 or apply security patch against 0.6.1 v
Bugzilla
CVE-2008-3108 Security Vulnerability with JRE fonts processing may allow Elevation of Privileges (6450319)
bugzilla·2008-07-09·CVSS 10.0
CVE-2008-3108 [CRITICAL] CVE-2008-3108 Security Vulnerability with JRE fonts processing may allow Elevation of Privileges (6450319)
CVE-2008-3108 Security Vulnerability with JRE fonts processing may allow Elevation of Privileges (6450319)
A buffer overflow security vulnerability with the processing of fonts in the
Java Runtime Environment (JRE) may allow an untrusted applet or application to
elevate its privileges. For example, an untrusted applet may grant itself
permissions to read and write local files or execute local applications that are
accessible to the user running the untrusted applet.
Discussion:
This issue has been corrected via:
Red Hat Network Satellite Server 5.1 (RHEL v.4 AS) (RHSA-2008:0638)
Red Hat Enterprise Linux version 4 Extras (RHSA-2008:0790)
RHEL Supplementary version 5 (RHSA-2008:0790)
http://lists.apple.com/archives/security-announce//2008/Sep/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-09/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-09/msg00002.htmlhttp://marc.info/?l=bugtraq&m=122331139823057&w=2http://secunia.com/advisories/31010http://secunia.com/advisories/31320http://secunia.com/advisories/31497http://secunia.com/advisories/31600http://secunia.com/advisories/31736http://secunia.com/advisories/32018http://secunia.com/advisories/32179http://secunia.com/advisories/32180http://secunia.com/advisories/33236http://secunia.com/advisories/33237http://secunia.com/advisories/37386http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-238666-1http://support.apple.com/kb/HT3178http://support.apple.com/kb/HT3179http://support.avaya.com/elmodocs2/security/ASA-2008-300.htmhttp://support.avaya.com/elmodocs2/security/ASA-2008-507.htmhttp://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=751014http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=756717http://www.redhat.com/support/errata/RHSA-2008-0790.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1043.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1044.htmlhttp://www.securityfocus.com/archive/1/497041/100/0/threadedhttp://www.securityfocus.com/bid/30147http://www.securitytracker.com/id?1020461http://www.us-cert.gov/cas/techalerts/TA08-193A.htmlhttp://www.vmware.com/security/advisories/VMSA-2008-0016.htmlhttp://www.vupen.com/english/advisories/2008/2056/referenceshttp://www.vupen.com/english/advisories/2008/2740https://exchange.xforce.ibmcloud.com/vulnerabilities/43656http://lists.apple.com/archives/security-announce//2008/Sep/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-09/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-09/msg00002.htmlhttp://marc.info/?l=bugtraq&m=122331139823057&w=2http://secunia.com/advisories/31010http://secunia.com/advisories/31320http://secunia.com/advisories/31497http://secunia.com/advisories/31600http://secunia.com/advisories/31736http://secunia.com/advisories/32018http://secunia.com/advisories/32179http://secunia.com/advisories/32180http://secunia.com/advisories/33236http://secunia.com/advisories/33237http://secunia.com/advisories/37386http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-238666-1http://support.apple.com/kb/HT3178http://support.apple.com/kb/HT3179http://support.avaya.com/elmodocs2/security/ASA-2008-300.htmhttp://support.avaya.com/elmodocs2/security/ASA-2008-507.htmhttp://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=751014http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=756717http://www.redhat.com/support/errata/RHSA-2008-0790.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1043.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1044.htmlhttp://www.securityfocus.com/archive/1/497041/100/0/threadedhttp://www.securityfocus.com/bid/30147http://www.securitytracker.com/id?1020461http://www.us-cert.gov/cas/techalerts/TA08-193A.htmlhttp://www.vmware.com/security/advisories/VMSA-2008-0016.htmlhttp://www.vupen.com/english/advisories/2008/2056/referenceshttp://www.vupen.com/english/advisories/2008/2740https://exchange.xforce.ibmcloud.com/vulnerabilities/43656
2008-07-09
Published