Executive Summary

Informations
NameCVE-2008-5356First vendor Publication2008-12-05
VendorCveLast vendor Modification2011-03-07

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score9.3Attack RangeNetwork
Cvss Impact Score10Attack ComplexityMedium
Cvss Expoit Score8.6AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Heap-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5356

CWE : Common Weakness Enumeration

idName
CWE-119Failure to Constrain Operations within the Bounds of a Memory Buffer

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:6494
 
Oval ID: oval:org.mitre.oval:def:6494
Title: Sun Java Runtime Environment TrueType font buffer overflow
Description: Heap-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file.
Family: unix Class: vulnerability
Reference(s): CVE-2008-5356
Version: 1
Platform(s): VMWare ESX Server 3.5
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application27
Application46
Application18

Open Source Vulnerability Database (OSVDB)

idDescription
50516Sun Java JDK / JRE TrueType Font Processing Heap Overflow

Internal Sources (Detail)

SourceUrl
BIDhttp://www.securityfocus.com/bid/32608
CERThttp://www.us-cert.gov/cas/techalerts/TA08-340A.html
CONFIRMhttp://support.avaya.com/elmodocs2/security/ASA-2008-485.htm
http://support.avaya.com/elmodocs2/security/ASA-2009-012.htm
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=829914...
http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2009/03/024431-01.pdf
GENTOOhttp://security.gentoo.org/glsa/glsa-200911-02.xml
HPhttp://marc.info/?l=bugtraq&m=123678756409861&w=2
http://marc.info/?l=bugtraq&m=123678756409861&w=2
IDEFENSEhttp://labs.idefense.com/intelligence/vulnerabilities/display.php?id=757
OSVDBhttp://osvdb.org/50516
REDHAThttp://rhn.redhat.com/errata/RHSA-2008-1018.html
http://rhn.redhat.com/errata/RHSA-2008-1025.html
http://www.redhat.com/support/errata/RHSA-2009-0016.html
http://www.redhat.com/support/errata/RHSA-2009-0369.html
https://rhn.redhat.com/errata/RHSA-2009-0466.html
SECUNIAhttp://secunia.com/advisories/32991
http://secunia.com/advisories/33015
http://secunia.com/advisories/33187
http://secunia.com/advisories/33710
http://secunia.com/advisories/34233
http://secunia.com/advisories/34259
http://secunia.com/advisories/34447
http://secunia.com/advisories/34605
http://secunia.com/advisories/34972
http://secunia.com/advisories/35065
http://secunia.com/advisories/37386
http://secunia.com/advisories/38539
SUNALERThttp://sunsolve.sun.com/search/document.do?assetkey=1-26-244987-1
SUSEhttp://lists.opensuse.org/opensuse-security-announce/2009-01/msg00009.html
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
VUPENhttp://www.vupen.com/english/advisories/2008/3339
http://www.vupen.com/english/advisories/2009/0672
XFhttp://xforce.iss.net/xforce/xfdb/47103

Alert History

If you want to see full details history, please login or register.
0
DateInformations
2013-05-11 00:31:46
  • Multiple Updates