First published: Wed Jul 09 2008(Updated: )
Unspecified vulnerability in the Virtual Machine in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenJDK | =5.0-update_12 | |
Sun JRE | =1.4.2_16 | |
OpenJDK | =5.0-update_3 | |
Sun JRE | =5.0-update_13 | |
Sun JRE | =5.0-update_1 | |
OpenJDK | =5.0-update_11 | |
Sun JRE | =1.4.2_01 | |
Sun JRE | <=5.0 | |
Sun SDK | =1.4.2_10 | |
Sun SDK | =1.4.2_12 | |
OpenJDK | =5.0-update_8 | |
Sun JRE | =5.0-update_14 | |
Sun JRE | =6-update_3 | |
Sun JRE | =6-update_4 | |
Sun JRE | =5.0-update_12 | |
Sun JRE | =1.4.2_03 | |
Sun SDK | =1.4.2_14 | |
OpenJDK | =5.0-update_1 | |
Sun JRE | =1.4.2_15 | |
Sun SDK | =1.4.2_04 | |
OpenJDK | =6-update_1 | |
OpenJDK | =6-update_3 | |
Sun JRE | =1.4.2_13 | |
Sun SDK | =1.4.2_13 | |
Sun JRE | =1.4.2_8 | |
OpenJDK | =5.0-update_5 | |
Sun JRE | =6-update_2 | |
Sun JRE | =5.0-update_4 | |
OpenJDK | =6-update_4 | |
Sun JRE | <=1.4.2_17 | |
Sun JRE | =1.4.2_06 | |
Sun JRE | =5.0-update_9 | |
Sun JRE | =1.4.2_12 | |
Sun JRE | =5.0-update_8 | |
Sun JRE | =5.0-update_7 | |
OpenJDK | =5.0-update_6 | |
Sun JRE | =1.4.2_07 | |
Sun JRE | =1.4.2_14 | |
Sun JRE | <=6 | |
Sun JRE | =6-update_5 | |
Sun SDK | =1.4.2_07 | |
OpenJDK | <=6 | |
OpenJDK | =5.0-update_14 | |
Sun JRE | =5.0-update_2 | |
Sun JRE | =1.4.2_10 | |
OpenJDK | =6-update_2 | |
Sun SDK | =1.4.2_09 | |
OpenJDK | =5.0-update_13 | |
Sun JRE | =5.0-update_5 | |
Sun JRE | =1.4.2_04 | |
Sun SDK | =1.4.2_02 | |
Sun JRE | =1.4.2_9 | |
Sun JRE | =1.4.2 | |
Sun SDK | =1.4.2_16 | |
Sun SDK | =1.4.2_11 | |
Sun JRE | =5.0-update_6 | |
Sun JRE | =5.0-update_11 | |
Sun JRE | =1.4.2_11 | |
Sun JRE | =1.4.2_05 | |
Sun JRE | =6-update_1 | |
OpenJDK | =6-update_5 | |
Sun SDK | =1.4.2_08 | |
Sun SDK | =1.4.2_03 | |
Sun SDK | <=1.4.2_17 | |
OpenJDK | =5.0-update_10 | |
Sun JRE | =1.4.2_3 | |
Sun SDK | =1.4.2_05 | |
OpenJDK | =5.0-update_2 | |
Sun JRE | =1.4.2_02 | |
Sun SDK | =1.4.2_06 | |
OpenJDK | <=5.0 | |
Sun SDK | =1.4.2_15 | |
OpenJDK | =5.0-update_4 | |
OpenJDK | =5.0-update_9 | |
Sun JRE | =5.0-update_3 | |
Sun JRE | =5.0-update_10 | |
OpenJDK | =5.0-update_7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3107 is considered a critical vulnerability that can allow context-dependent attackers to gain privileges.
To fix CVE-2008-3107, update your Java Runtime Environment to the latest version available, specifically JRE 6 Update 7 or higher.
CVE-2008-3107 affects JDK and JRE 6 before Update 7, and JDK and JRE 5.0 before Update 16, along with SDK and JRE 1.4.x before 1.4.2_18.
CVE-2008-3107 relates to vulnerabilities in the Virtual Machine in Sun Java Runtime Environment that can lead to privilege escalation.
It is highly discouraged to use software affected by CVE-2008-3107 without applying relevant patches or updates, as it poses a significant security risk.