Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2008-5352
StatusCandidate
DescriptionInteger overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack.dll) in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted applications and applets to gain privileges via a Pack200 compressed JAR file that triggers a heap-based buffer overflow.
PhaseAssigned (04.12.2008)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-5352
ReferencesBID : 32608
 CERT : TA08-340A
 IDEFENSE : 20081204 Sun Java JRE Pack200 Decompression Integer Overflow Vulnerability
 REDHAT : RHSA-2008:1018
 REDHAT : RHSA-2008:1025
 REDHAT : RHSA-2009:0015
 SECUNIA : 32991
 SECUNIA : 33015
 SECUNIA : 33528
 SECUNIA : 33709
 SECUNIA : 33710
 SUNALERT : 244992
 SUSE : SUSE-SA:2009:007
 VUPEN : ADV-2008-3339
SecurityVulns:Sun Java JRE / JDK / Web Start multiple security vulnerabilities

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server