java-1.5.0 Privilege escalation via unstrusted applet and application
Published Feb 7, 2008
10.0
HIGHCVSS 2.0
EPSS 2.84%
Description
Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 and earlier, and 5.0 Update 13 and earlier, allow context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.
Affected products
No data.
No data.
Extras for RHEL 4
java-1.5.0-ibm-1:1.5.0.7-1jpp.2.el4
Fixed · RHSA-2008:0210
Extras for RHEL 4
java-1.5.0-sun-0:1.5.0.14-1jpp.2.el4
Fixed · RHSA-2008:0123
Red Hat Network Satellite Server v 5.1
java-1.5.0-ibm-1:1.5.0.8-1jpp.1.el4
Fixed · RHSA-2008:0638
Supplementary for Red Hat Enterprise Linux 5
java-1.5.0-bea-0:1.5.0.14-1jpp.1.el5
Fixed · RHSA-2008:0156
Supplementary for Red Hat Enterprise Linux 5
java-1.5.0-ibm-1:1.5.0.7-1jpp.2.el5
Fixed · RHSA-2008:0210
Supplementary for Red Hat Enterprise Linux 5
java-1.5.0-sun-0:1.5.0.14-1jpp.2.el5
Fixed · RHSA-2008:0123
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 4 | java-1.5.0-ibm-1:1.5.0.7-1jpp.2.el4 | Fixed | RHSA-2008:0210 |
| Extras for RHEL 4 | java-1.5.0-sun-0:1.5.0.14-1jpp.2.el4 | Fixed | RHSA-2008:0123 |
| Red Hat Network Satellite Server v 5.1 | java-1.5.0-ibm-1:1.5.0.8-1jpp.1.el4 | Fixed | RHSA-2008:0638 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.5.0-bea-0:1.5.0.14-1jpp.1.el5 | Fixed | RHSA-2008:0156 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.5.0-ibm-1:1.5.0.7-1jpp.2.el5 | Fixed | RHSA-2008:0210 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.5.0-sun-0:1.5.0.14-1jpp.2.el5 | Fixed | RHSA-2008:0123 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (30)
- http://dev2dev.bea.com/pub/advisory/277 vendor-advisoryx_refsource_BEA
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/28795 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/28888 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29214 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29498 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29841 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29858 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29897 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30676 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30780 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31497 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200804-28.xml vendor-advisoryx_refsource_GENTOO
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-231261-1 vendor-advisoryx_refsource_SUNALERT
- http://www.gentoo.org/security/en/glsa/glsa-200804-20.xml vendor-advisoryx_refsource_GENTOO
- http://www.gentoo.org/security/en/glsa/glsa-200806-11.xml vendor-advisoryx_refsource_GENTOO
- http://www.redhat.com/support/errata/RHSA-2008-0123.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0156.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0210.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/27650 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1019308 vdb-entryx_refsource_SECTRACK
- http://www.vmware.com/security/advisories/VMSA-2008-0010.html x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2008/0429 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/1252 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/1856/references vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2008-0657 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=431861 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2008-0657
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11505 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2008-0657
Change history (0)
No recorded changes yet.