9.3

CVE-2008-5356

Heap-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sun ≫ Jdk Update update_16 Version <= 5.0
Sun ≫ Jdk Update update_10 Version <= 6
Sun ≫ Jdk Version 5.0 Update update_1
Sun ≫ Jdk Version 5.0 Update update_10
Sun ≫ Jdk Version 5.0 Update update_11
Sun ≫ Jdk Version 5.0 Update update_12
Sun ≫ Jdk Version 5.0 Update update_13
Sun ≫ Jdk Version 5.0 Update update_14
Sun ≫ Jdk Version 5.0 Update update_15
Sun ≫ Jdk Version 5.0 Update update_2
Sun ≫ Jdk Version 5.0 Update update_3
Sun ≫ Jdk Version 5.0 Update update_4
Sun ≫ Jdk Version 5.0 Update update_5
Sun ≫ Jdk Version 5.0 Update update_6
Sun ≫ Jdk Version 5.0 Update update_7
Sun ≫ Jdk Version 5.0 Update update_8
Sun ≫ Jdk Version 5.0 Update update_9
Sun ≫ Jdk Version 6
Sun ≫ Jdk Version 6 Update update_1
Sun ≫ Jdk Version 6 Update update_2
Sun ≫ Jdk Version 6 Update update_3
Sun ≫ Jdk Version 6 Update update_4
Sun ≫ Jdk Version 6 Update update_5
Sun ≫ Jdk Version 6 Update update_6
Sun ≫ Jdk Version 6 Update update_7
Sun ≫ Jdk Version 6 Update update_8
Sun ≫ Jdk Version 6 Update update_9
Sun ≫ Jre Version <= 1.4.2_18
Sun ≫ Jre Update update_16 Version <= 5.0
Sun ≫ Jre Update update_10 Version <= 6
Sun ≫ Jre Version 1.4.2_1
Sun ≫ Jre Version 1.4.2_2
Sun ≫ Jre Version 1.4.2_3
Sun ≫ Jre Version 1.4.2_4
Sun ≫ Jre Version 1.4.2_5
Sun ≫ Jre Version 1.4.2_6
Sun ≫ Jre Version 1.4.2_7
Sun ≫ Jre Version 1.4.2_8
Sun ≫ Jre Version 1.4.2_9
Sun ≫ Jre Version 1.4.2_10
Sun ≫ Jre Version 1.4.2_11
Sun ≫ Jre Version 1.4.2_12
Sun ≫ Jre Version 1.4.2_13
Sun ≫ Jre Version 1.4.2_14
Sun ≫ Jre Version 1.4.2_15
Sun ≫ Jre Version 1.4.2_16
Sun ≫ Jre Version 1.4.2_17
Sun ≫ Jre Version 5.0
Sun ≫ Jre Version 5.0 Update update_1
Sun ≫ Jre Version 5.0 Update update_10
Sun ≫ Jre Version 5.0 Update update_11
Sun ≫ Jre Version 5.0 Update update_12
Sun ≫ Jre Version 5.0 Update update_13
Sun ≫ Jre Version 5.0 Update update_14
Sun ≫ Jre Version 5.0 Update update_15
Sun ≫ Jre Version 5.0 Update update_2
Sun ≫ Jre Version 5.0 Update update_3
Sun ≫ Jre Version 5.0 Update update_4
Sun ≫ Jre Version 5.0 Update update_5
Sun ≫ Jre Version 5.0 Update update_6
Sun ≫ Jre Version 5.0 Update update_7
Sun ≫ Jre Version 5.0 Update update_8
Sun ≫ Jre Version 5.0 Update update_9
Sun ≫ Jre Version 6
Sun ≫ Jre Version 6 Update update_1
Sun ≫ Jre Version 6 Update update_2
Sun ≫ Jre Version 6 Update update_3
Sun ≫ Jre Version 6 Update update_4
Sun ≫ Jre Version 6 Update update_5
Sun ≫ Jre Version 6 Update update_6
Sun ≫ Jre Version 6 Update update_7
Sun ≫ Jre Version 6 Update update_8
Sun ≫ Jre Version 6 Update update_9
Sun ≫ Sdk Version <= 1.4.2_18
Sun ≫ Sdk Version 1.4.2_1
Sun ≫ Sdk Version 1.4.2_2
Sun ≫ Sdk Version 1.4.2_3
Sun ≫ Sdk Version 1.4.2_4
Sun ≫ Sdk Version 1.4.2_5
Sun ≫ Sdk Version 1.4.2_6
Sun ≫ Sdk Version 1.4.2_7
Sun ≫ Sdk Version 1.4.2_8
Sun ≫ Sdk Version 1.4.2_9
Sun ≫ Sdk Version 1.4.2_10
Sun ≫ Sdk Version 1.4.2_11
Sun ≫ Sdk Version 1.4.2_12
Sun ≫ Sdk Version 1.4.2_13
Sun ≫ Sdk Version 1.4.2_14
Sun ≫ Sdk Version 1.4.2_15
Sun ≫ Sdk Version 1.4.2_16
Sun ≫ Sdk Version 1.4.2_17
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.91% 0.946
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.html
http://secunia.com/advisories/34259
http://secunia.com/advisories/34972
http://secunia.com/advisories/37386
http://security.gentoo.org/glsa/glsa-200911-02.xml
https://rhn.redhat.com/errata/RHSA-2009-0466.html
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
http://secunia.com/advisories/35065
http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00009.html
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00004.html
http://marc.info/?l=bugtraq&m=123678756409861&w=2
http://marc.info/?l=bugtraq&m=126583436323697&w=2
http://rhn.redhat.com/errata/RHSA-2008-1025.html
http://secunia.com/advisories/32991
http://secunia.com/advisories/33015
http://secunia.com/advisories/33710
http://secunia.com/advisories/34233
http://secunia.com/advisories/34605
http://secunia.com/advisories/38539
http://support.avaya.com/elmodocs2/security/ASA-2009-012.htm
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=829914&poid=
http://www.redhat.com/support/errata/RHSA-2009-0016.html
http://www.us-cert.gov/cas/techalerts/TA08-340A.html
US Government Resource
http://www.vupen.com/english/advisories/2009/0672
http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2009/03/024431-01.pdf
http://rhn.redhat.com/errata/RHSA-2008-1018.html
http://www.vupen.com/english/advisories/2008/3339
http://secunia.com/advisories/34447
http://www.redhat.com/support/errata/RHSA-2009-0369.html
http://www.securityfocus.com/bid/32608
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=757
http://osvdb.org/50516
http://secunia.com/advisories/33187
http://sunsolve.sun.com/search/document.do?assetkey=1-26-244987-1
Patch
Vendor Advisory
http://support.avaya.com/elmodocs2/security/ASA-2008-485.htm
https://exchange.xforce.ibmcloud.com/vulnerabilities/47103
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6494