CVE-2008-5352
published 2008-12-05CVE-2008-5352: Integer overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack.dll) in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10…
PriorityP343critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.06%
86.1th percentile
Integer overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack.dll) in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted applications and applets to gain privileges via a Pack200 compressed JAR file that triggers a heap-based buffer overflow.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 5.0 | — |
| sun | jdk | <= 6 | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | <= 5.0 | — |
| sun | jre | <= 6 | — |
| sun | jre | — | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
openjdk-6 vulnerabilities
vendor_ubuntu·2009-01-27·CVSS 7.5
CVE-2008-5352 [HIGH] openjdk-6 vulnerabilities
Title: openjdk-6 vulnerabilities
Summary: openjdk-6 vulnerabilities
It was discovered that Java did not correctly handle untrusted applets.
If a user were tricked into running a malicious applet, a remote attacker
could gain user privileges, or list directory contents. (CVE-2008-5347,
CVE-2008-5350)
It was discovered that Kerberos authentication and RSA public key
processing were not correctly handled in Java. A remote attacker
could exploit these flaws to cause a denial of service. (CVE-2008-5348,
CVE-2008-5349)
It was discovered that Java accepted UTF-8 encodings that might be
handled incorrectly by certain applications. A remote attacker could
bypass string filters, possible leading to other exploits. (CVE-2008-5351)
Overflows were discovered in Java JAR processing. If a user or
au
Red Hat
OpenJDK Jar200 Decompression buffer overflow (6755943)
vendor_redhat·2008-12-04·CVSS 9.3
CVE-2008-5352 [CRITICAL] OpenJDK Jar200 Decompression buffer overflow (6755943)
OpenJDK Jar200 Decompression buffer overflow (6755943)
Integer overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack.dll) in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted applications and applets to gain privileges via a Pack200 compressed JAR file that triggers a heap-based buffer overflow.
GHSA
GHSA-pfr6-j3gf-9m85: Integer overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack
ghsa_unreviewed·2022-05-17
CVE-2008-5352 [HIGH] GHSA-pfr6-j3gf-9m85: Integer overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack
Integer overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack.dll) in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted applications and applets to gain privileges via a Pack200 compressed JAR file that triggers a heap-based buffer overflow.
No detection rules found.
No public exploits indexed.
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=759http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.htmlhttp://osvdb.org/50501http://rhn.redhat.com/errata/RHSA-2008-1018.htmlhttp://rhn.redhat.com/errata/RHSA-2008-1025.htmlhttp://secunia.com/advisories/32991http://secunia.com/advisories/33015http://secunia.com/advisories/33528http://secunia.com/advisories/33709http://secunia.com/advisories/33710http://secunia.com/advisories/34259http://secunia.com/advisories/34972http://secunia.com/advisories/37386http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-244992-1http://support.avaya.com/elmodocs2/security/ASA-2009-012.htmhttp://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=829914&poid=http://www.redhat.com/support/errata/RHSA-2009-0015.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0016.htmlhttp://www.securityfocus.com/bid/32608http://www.securitytracker.com/id?1021312http://www.us-cert.gov/cas/techalerts/TA08-340A.htmlhttp://www.vupen.com/english/advisories/2008/3339http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2009/03/024431-01.pdfhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6383https://rhn.redhat.com/errata/RHSA-2009-0466.htmlhttp://labs.idefense.com/intelligence/vulnerabilities/display.php?id=759http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.htmlhttp://osvdb.org/50501http://rhn.redhat.com/errata/RHSA-2008-1018.htmlhttp://rhn.redhat.com/errata/RHSA-2008-1025.htmlhttp://secunia.com/advisories/32991http://secunia.com/advisories/33015http://secunia.com/advisories/33528http://secunia.com/advisories/33709http://secunia.com/advisories/33710http://secunia.com/advisories/34259http://secunia.com/advisories/34972http://secunia.com/advisories/37386http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-244992-1http://support.avaya.com/elmodocs2/security/ASA-2009-012.htmhttp://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=829914&poid=http://www.redhat.com/support/errata/RHSA-2009-0015.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0016.htmlhttp://www.securityfocus.com/bid/32608http://www.securitytracker.com/id?1021312http://www.us-cert.gov/cas/techalerts/TA08-340A.htmlhttp://www.vupen.com/english/advisories/2008/3339http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2009/03/024431-01.pdfhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6383https://rhn.redhat.com/errata/RHSA-2009-0466.html
2008-12-05
Published