CVE-2008-5359Improper Restriction of Operations within the Bounds of a Memory Buffer in JDK

Severity
9.3CRITICALNVD
EPSS
35.1%
top 2.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 5
Latest updateMay 13

Description

Buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code, related to a ConvolveOp operation in the Java AWT library.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages3 packages

NVDsun/jdk1.5.0, 1.6.0+1
NVDsun/jre44 versions+43
NVDsun/sdk49 versions+48

Patches

🔴Vulnerability Details

2
GHSA
GHSA-cq8v-6hvc-rjqq: Buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 52022-05-13
CVEList
CVE-2008-5359: Buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 52008-12-05

📋Vendor Advisories

2
Ubuntu
openjdk-6 vulnerabilities2009-01-27
Red Hat
OpenJDK Buffer overflow in image processing (6726779)2008-12-04

💬Community

1
Bugzilla
CVE-2008-5359 OpenJDK Buffer overflow in image processing (6726779)2008-11-19
CVE-2008-5359 — SUN JDK vulnerability | cvebase