First published: Wed Jul 09 2008(Updated: )
Multiple unspecified vulnerabilities in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allow remote attackers to violate the security model for an applet's outbound connections by connecting to localhost services running on the machine that loaded the applet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun SDK | =1.3.1_03 | |
OpenJDK | =5.0-update_12 | |
Sun JRE | =1.4.2_7 | |
Sun JRE | =1.4.2_16 | |
Sun JRE | =1.3.1_02 | |
Sun JRE | =1.3.1 | |
Sun JRE | =1.3.1_10 | |
Sun JRE | =1.3.1_06 | |
Sun SDK | =1.4.2 | |
OpenJDK | =5.0-update_3 | |
Sun SDK | =1.3.1_19 | |
OpenJDK | =5.0-update_11 | |
Sun JRE | =1.4.2_4 | |
Sun SDK | =1.3.1_08 | |
Sun JRE | =1.3.1-update19 | |
Sun SDK | =1.4.2_10 | |
Sun SDK | =1.4.2_12 | |
Sun JRE | =1.4.2_2 | |
OpenJDK | =5.0-update_8 | |
Sun JRE | =1.3.1_22 | |
Sun SDK | =1.3.1_15 | |
Sun SDK | =1.4.2_14 | |
OpenJDK | =5.0-update_1 | |
Sun JRE | =1.4.2_15 | |
Sun SDK | =1.4.2_04 | |
OpenJDK | =6-update_1 | |
Sun SDK | =1.4.2_01 | |
OpenJDK | =6-update_3 | |
Sun JRE | =1.4.2_13 | |
Sun JRE | =1.4.2_1 | |
Sun SDK | =1.4.2_13 | |
Sun JRE | =1.4.2_8 | |
OpenJDK | =5.0-update_5 | |
Sun JRE | =1.3.1-update20 | |
OpenJDK | =6-update_4 | |
Sun JRE | =1.3.1_11 | |
Sun SDK | =1.3.1_07 | |
Sun JRE | =1.3.1_17 | |
Sun SDK | =1.3.1_10 | |
Sun JRE | =1.4.2_12 | |
Sun JRE | =1.3.1_12 | |
Sun SDK | =1.3.1_06 | |
Sun JRE | =1.3.1_03 | |
Sun SDK | =1.3.1_12 | |
Sun JRE | =1.3.1_14 | |
OpenJDK | =5.0-update_6 | |
Sun SDK | =1.3.1_20 | |
Sun SDK | =1.3.1_17 | |
Sun JRE | =1.3.1_08 | |
Sun SDK | =1.3.1_02 | |
Sun SDK | =1.3.1_18 | |
Sun SDK | =1.3.1_01 | |
Sun JRE | =1.4.2_14 | |
Sun JRE | =1.3.1_07 | |
Sun SDK | =1.3.1_16 | |
Sun SDK | =1.4.2_07 | |
OpenJDK | <=6 | |
Sun JRE | =1.3.1_05 | |
OpenJDK | =5.0-update_14 | |
Sun JRE | =1.3.0 | |
Sun SDK | =1.3.1_22 | |
Sun JRE | =1.4.2_10 | |
Sun JRE | =1.4.2_17 | |
Sun SDK | =1.3.1_14 | |
OpenJDK | =6-update_2 | |
Sun SDK | =1.3.1_13 | |
Sun SDK | =1.4.2_09 | |
OpenJDK | =5.0-update_13 | |
Sun JRE | =1.3.1-update16 | |
Sun SDK | =1.4.2_02 | |
Sun JRE | =1.4.2_9 | |
Sun SDK | =1.3.0 | |
Sun SDK | =1.4.2_16 | |
Sun SDK | =1.4.2_11 | |
Sun JRE | =1.3.1_13 | |
Sun JRE | =1.3.1_04 | |
Sun SDK | =1.3.1_09 | |
OpenJDK | =1.5.0-update_12 | |
Sun JRE | =1.3.1_09 | |
Sun JRE | =1.4.2_11 | |
Sun SDK | =1.3.1_04 | |
OpenJDK | =6-update_5 | |
Sun JRE | =1.3.1_15 | |
Sun SDK | =1.3.1_21 | |
Sun SDK | =1.4.2_08 | |
Sun SDK | =1.3.1_05 | |
Sun SDK | =1.4.2_03 | |
Sun JRE | =1.3.1-update18 | |
OpenJDK | =5.0-update_10 | |
Sun JRE | =1.4.2_3 | |
Sun SDK | =1.4.2_05 | |
Sun JRE | =1.4.2_5 | |
OpenJDK | =5.0-update_2 | |
Sun SDK | =1.4.2_06 | |
OpenJDK | <=5.0 | |
Sun SDK | =1.3.1_11 | |
Sun SDK | =1.4.2_15 | |
OpenJDK | =5.0-update_4 | |
OpenJDK | =5.0-update_9 | |
Sun JRE | =1.3.1_21 | |
Sun JRE | =1.4.2_6 | |
OpenJDK | =5.0-update_7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-3104 is categorized as a critical vulnerability that can lead to significant security breaches in affected Java Runtime Environment versions.
To fix CVE-2008-3104, you need to upgrade to the latest version of the Java Runtime Environment that is not affected by this vulnerability.
CVE-2008-3104 affects Sun JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, as well as several versions of SDK and JRE 1.4.x and 1.3.x.
CVE-2008-3104 can be exploited by remote attackers to bypass security restrictions and potentially execute arbitrary code.
If you cannot upgrade due to compatibility issues, consider disabling Java applets or using alternative runtime environments until an upgrade is possible.