CVE-2008-5343
published 2008-12-05CVE-2008-5343: Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier…
PriorityP346critical9CVSS 2.0
AVNACLAuNCCIPAP
EPSS
5.09%
91.4th percentile
Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows remote attackers to make unauthorized network connections and hijack HTTP sessions via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR" and CR 6707535.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 5.0 | — |
| sun | jdk | <= 6 | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | <= 1.4.2_18 | — |
| sun | jre | <= 5.0 | — |
| sun | jre | <= 6 | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:N/C:C/I:P/A:P
vendor_redhat9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-48xx-r45r-42qg: Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5
ghsa_unreviewed·2022-05-17
CVE-2008-5343 [HIGH] GHSA-48xx-r45r-42qg: Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5
Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows remote attackers to make unauthorized network connections and hijack HTTP sessions via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR" and CR 6707535.
Red Hat
Java WebStart allows hidden code privilege escalation
vendor_redhat·2008-12-04·CVSS 9.0
CVE-2008-5343 [CRITICAL] Java WebStart allows hidden code privilege escalation
Java WebStart allows hidden code privilege escalation
Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows remote attackers to make unauthorized network connections and hijack HTTP sessions via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR" and CR 6707535.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1927 icedtea-web: GIFAR issue
bugzilla·2012-12-06·CVSS 9.0
CVE-2013-1927 [CRITICAL] CVE-2013-1927 icedtea-web: GIFAR issue
CVE-2013-1927 icedtea-web: GIFAR issue
Current IcedTea-Web versions are affected by GIFAR issue. It is possible to combine GIF image with Java JAR into a single file, that is both valid GIF as well as valid JAR/ZIP file. This issue can be used to execute Java applet in the context of the site that allows untrusted users to upload images in GIF format.
This problem was previously fixed in Oracle and IBM Java plugins as CVE-2008-5343 (bug 474790).
References:
http://en.wikipedia.org/wiki/Gifar
http://xs-sniper.com/blog/2008/12/17/sun-fixes-gifars/
http://riosec.com/how-to-create-a-gifar
Discussion:
Created attachment 659469
proposed patch
This patch is fixing the issue. Troubles will come when not just zip jars will be used (and so jar header will change) - eg pack2000 in jdk8.
Otherwi
Bugzilla
CVE-2008-5343 Java WebStart allows hidden code privilege escalation
bugzilla·2008-12-05·CVSS 9.0
CVE-2008-5343 [CRITICAL] CVE-2008-5343 Java WebStart allows hidden code privilege escalation
CVE-2008-5343 Java WebStart allows hidden code privilege escalation
Name: CVE-2008-5343
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5343
Reference: SUNALERT:244988
Reference: URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-244988-1
Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in
with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update
16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows "hidden
code" to make unauthorized network connections and "hijack HTTP
sessions using cookies stored in the browser" via unknown vectors.
Discussion:
Another mention of this issue:
http://secunia.com/advisories/32991/
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Ente
http://lists.apple.com/archives/security-announce/2009/Feb/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-01/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlhttp://marc.info/?l=bugtraq&m=123678756409861&w=2http://marc.info/?l=bugtraq&m=126583436323697&w=2http://osvdb.org/50512http://rhn.redhat.com/errata/RHSA-2008-1018.htmlhttp://rhn.redhat.com/errata/RHSA-2008-1025.htmlhttp://secunia.com/advisories/32991http://secunia.com/advisories/33015http://secunia.com/advisories/33710http://secunia.com/advisories/34233http://secunia.com/advisories/34447http://secunia.com/advisories/34605http://secunia.com/advisories/34889http://secunia.com/advisories/35065http://secunia.com/advisories/37386http://secunia.com/advisories/38539http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-244988-1http://support.avaya.com/elmodocs2/security/ASA-2008-486.htmhttp://support.avaya.com/elmodocs2/security/ASA-2009-012.htmhttp://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=829914&poid=http://www.redhat.com/support/errata/RHSA-2009-0016.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0369.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0445.htmlhttp://www.securityfocus.com/bid/32892http://www.us-cert.gov/cas/techalerts/TA08-340A.htmlhttp://www.vupen.com/english/advisories/2008/3339http://www.vupen.com/english/advisories/2009/0424http://www.vupen.com/english/advisories/2009/0672http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2009/03/024431-01.pdfhttp://xs-sniper.com/blog/2008/12/17/sun-fixes-gifars/https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5924http://lists.apple.com/archives/security-announce/2009/Feb/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-01/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlhttp://marc.info/?l=bugtraq&m=123678756409861&w=2http://marc.info/?l=bugtraq&m=126583436323697&w=2http://osvdb.org/50512http://rhn.redhat.com/errata/RHSA-2008-1018.htmlhttp://rhn.redhat.com/errata/RHSA-2008-1025.htmlhttp://secunia.com/advisories/32991http://secunia.com/advisories/33015http://secunia.com/advisories/33710http://secunia.com/advisories/34233http://secunia.com/advisories/34447http://secunia.com/advisories/34605http://secunia.com/advisories/34889http://secunia.com/advisories/35065http://secunia.com/advisories/37386http://secunia.com/advisories/38539http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-244988-1http://support.avaya.com/elmodocs2/security/ASA-2008-486.htmhttp://support.avaya.com/elmodocs2/security/ASA-2009-012.htmhttp://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=829914&poid=http://www.redhat.com/support/errata/RHSA-2009-0016.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0369.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0445.htmlhttp://www.securityfocus.com/bid/32892http://www.us-cert.gov/cas/techalerts/TA08-340A.htmlhttp://www.vupen.com/english/advisories/2008/3339http://www.vupen.com/english/advisories/2009/0424http://www.vupen.com/english/advisories/2009/0672http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2009/03/024431-01.pdfhttp://xs-sniper.com/blog/2008/12/17/sun-fixes-gifars/https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5924
2008-12-05
Published