CVE-2008-3111: Buffer Overflow
Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.218 allow context-dependent attackers to gain privileges via an untrusted application, as demonstrated by (a) an application that grants itself privileges to (1) read local files, (2) write to local files, or (3) execute local programs; and as demonstrated by (b) a long value associated with a java-vm-args attribute in a j2se tag in a JNLP file, which triggers a stack-based buffer overflow in the GetVMArgsOption function; aka CR 6557220.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3111?
The severity of CVE-2008-3111 is classified as high due to its potential to allow context-dependent attackers to gain elevated privileges.
How do I fix CVE-2008-3111?
To fix CVE-2008-3111, you should update your JDK or JRE to the latest version or apply the relevant security patches provided by Sun.
Which versions are affected by CVE-2008-3111?
CVE-2008-3111 affects JDK and JRE 6 before Update 4, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18.
What type of vulnerability is CVE-2008-3111?
CVE-2008-3111 is a buffer overflow vulnerability found in Sun Java Web Start.
Who can exploit CVE-2008-3111?
Context-dependent attackers can exploit CVE-2008-3111 through specially crafted untrusted applications.