CVE-2008-5358
published 2008-12-05CVE-2008-5358: Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier might allow remote attackers to execute arbitrary code via a crafted GIF file that…
PriorityP347critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
7.43%
93.7th percentile
Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier might allow remote attackers to execute arbitrary code via a crafted GIF file that triggers memory corruption during display of the splash screen, possibly related to splashscreen.dll.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 6 | — |
| sun | jdk | — | — |
| sun | jre | <= 6 | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
openjdk-6 vulnerabilities
vendor_ubuntu·2009-01-27·CVSS 7.5
CVE-2008-5352 [HIGH] openjdk-6 vulnerabilities
Title: openjdk-6 vulnerabilities
Summary: openjdk-6 vulnerabilities
It was discovered that Java did not correctly handle untrusted applets.
If a user were tricked into running a malicious applet, a remote attacker
could gain user privileges, or list directory contents. (CVE-2008-5347,
CVE-2008-5350)
It was discovered that Kerberos authentication and RSA public key
processing were not correctly handled in Java. A remote attacker
could exploit these flaws to cause a denial of service. (CVE-2008-5348,
CVE-2008-5349)
It was discovered that Java accepted UTF-8 encodings that might be
handled incorrectly by certain applications. A remote attacker could
bypass string filters, possible leading to other exploits. (CVE-2008-5351)
Overflows were discovered in Java JAR processing. If a user or
au
Red Hat
OpenJDK Buffer Overflow in GIF image processing (6766136)
vendor_redhat·2008-12-04·CVSS 9.3
CVE-2008-5358 [CRITICAL] OpenJDK Buffer Overflow in GIF image processing (6766136)
OpenJDK Buffer Overflow in GIF image processing (6766136)
Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier might allow remote attackers to execute arbitrary code via a crafted GIF file that triggers memory corruption during display of the splash screen, possibly related to splashscreen.dll.
GHSA
GHSA-92q9-fg9g-832c: Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier might allow remote attackers to execute arbitrary code via a crafted GIF fi
ghsa_unreviewed·2022-05-17
CVE-2008-5358 [HIGH] CWE-119 GHSA-92q9-fg9g-832c: Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier might allow remote attackers to execute arbitrary code via a crafted GIF fi
Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier might allow remote attackers to execute arbitrary code via a crafted GIF file that triggers memory corruption during display of the splash screen, possibly related to splashscreen.dll.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-5358 OpenJDK Buffer Overflow in GIF image processing (6766136)
bugzilla·2008-11-19·CVSS 9.3
CVE-2008-5358 [CRITICAL] CVE-2008-5358 OpenJDK Buffer Overflow in GIF image processing (6766136)
CVE-2008-5358 OpenJDK Buffer Overflow in GIF image processing (6766136)
Name: CVE-2008-5358
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5358
Reference: IDEFENSE:20081204 Sun Java Web Start GIF Decoding Memory Corruption Vulnerability
Reference: URL:http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=758
Reference: SUNALERT:244987
Reference: URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-244987-1
Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and
earlier might allow remote attackers to execute arbitrary code via a
crafted GIF file that triggers memory corruption during display of the
splash screen, possibly related to splashscreen.dll.
Discussion:
java-1.6.0-openjdk-1.6.0.0-0.20.b09.fc9 has been pushed to t
Bugzilla
CVE-2008-0658 openldap: slapd crash on modrdn operation with NOOP control on entry in bdb storage
bugzilla·2008-02-08·CVSS 4.0
CVE-2008-0658 [MEDIUM] CVE-2008-0658 openldap: slapd crash on modrdn operation with NOOP control on entry in bdb storage
CVE-2008-0658 openldap: slapd crash on modrdn operation with NOOP control on entry in bdb storage
While preparing the patch for CVE-2007-6698 (issue allowing slapd daemon crash
using modify requests with NOOP control, tracked via bug bug #431203), it was
discovered, that similar crash can be achieved using modrdn operation with NOOP
control.
Upstream bug report:
http://www.openldap.org/its/index.cgi/Software%20Bugs?id=5358
Patch applied in upstream CVS:
http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/back-bdb/modrdn.c.diff?r1=1.197&r2=1.198&f=h
Discussion:
Similar to CVE-2007-6698, this issue does not affect OpenLDAP packages as
shipped in Red Hat Enterprise Linux 2.1 and 3, as they do not support NOOP
controls. Packages shipped in Red Hat Enterprise Linux 4 and 5 are affected.
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=758http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00004.htmlhttp://marc.info/?l=bugtraq&m=123678756409861&w=2http://marc.info/?l=bugtraq&m=126583436323697&w=2http://osvdb.org/50515http://rhn.redhat.com/errata/RHSA-2008-1018.htmlhttp://secunia.com/advisories/32991http://secunia.com/advisories/33015http://secunia.com/advisories/33187http://secunia.com/advisories/33709http://secunia.com/advisories/34233http://secunia.com/advisories/34259http://secunia.com/advisories/34447http://secunia.com/advisories/34605http://secunia.com/advisories/37386http://secunia.com/advisories/38539http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-244987-1http://support.avaya.com/elmodocs2/security/ASA-2008-485.htmhttp://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=829914&poid=http://www.redhat.com/support/errata/RHSA-2009-0369.htmlhttp://www.securityfocus.com/bid/32608http://www.us-cert.gov/cas/techalerts/TA08-340A.htmlhttp://www.vupen.com/english/advisories/2008/3339http://www.vupen.com/english/advisories/2009/0672http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2009/03/024431-01.pdfhttps://exchange.xforce.ibmcloud.com/vulnerabilities/47049https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6319http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=758http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00004.htmlhttp://marc.info/?l=bugtraq&m=123678756409861&w=2http://marc.info/?l=bugtraq&m=126583436323697&w=2http://osvdb.org/50515http://rhn.redhat.com/errata/RHSA-2008-1018.htmlhttp://secunia.com/advisories/32991http://secunia.com/advisories/33015http://secunia.com/advisories/33187http://secunia.com/advisories/33709http://secunia.com/advisories/34233http://secunia.com/advisories/34259http://secunia.com/advisories/34447http://secunia.com/advisories/34605http://secunia.com/advisories/37386http://secunia.com/advisories/38539http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-244987-1http://support.avaya.com/elmodocs2/security/ASA-2008-485.htmhttp://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=829914&poid=http://www.redhat.com/support/errata/RHSA-2009-0369.htmlhttp://www.securityfocus.com/bid/32608http://www.us-cert.gov/cas/techalerts/TA08-340A.htmlhttp://www.vupen.com/english/advisories/2008/3339http://www.vupen.com/english/advisories/2009/0672http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2009/03/024431-01.pdfhttps://exchange.xforce.ibmcloud.com/vulnerabilities/47049https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6319
2008-12-05
Published