cbcvebase.
CVE-2008-5359
published 2008-12-05

CVE-2008-5359: Buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and…

PriorityP352critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
10.78%
95.4th percentile
Buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code, related to a ConvolveOp operation in the Java AWT library.

Affected

95 ranges· showing 25
VendorProductVersion rangeFixed in
sunjdk
sunjdk
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered via a ConvolveOp operation in the Java AWT library — monitor for malicious image processing activity in Java applications using ConvolveOp
  • Affected versions for detection/patching scope: Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; SDK and JRE 1.3.1_23 and earlier
  • Attack vector is remote and involves image processing code — inspect untrusted image files processed by vulnerable JRE versions
  • ·Sun advisory reference 244987 may contain additional technical details; original source (sunsolve) is likely no longer accessible
  • ·Fixed in java-1.6.0-openjdk-1.6.0.0-0.20.b09.fc9 (Fedora 9) and java-1.6.0-openjdk-1.6.0.0-7.b12.fc10 (Fedora 10); RHEL addressed via RHSA-2009:0445 and RHSA-2009:0466

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.