CVE-2008-3112: Critical severity java development kit (jdk) vulnerability
Directory traversal vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.218 allows remote attackers to create arbitrary files via the writeManifest method in the CacheEntry class, aka CR 6703909.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3112?
CVE-2008-3112 is considered a high severity vulnerability due to its exploitation potential for arbitrary file creation.
How do I fix CVE-2008-3112?
To fix CVE-2008-3112, you should upgrade to JDK or JRE version 6 Update 7 or later, or JDK and JRE version 5.0 Update 16 or later.
Which systems are affected by CVE-2008-3112?
CVE-2008-3112 affects Sun Java Web Start in JDK and JRE versions prior to Update 7 for 6.x and Update 16 for 5.x, as well as SDK and JRE 1.4.x before 1.4.2_18.
What type of vulnerability is CVE-2008-3112?
CVE-2008-3112 is a directory traversal vulnerability that allows remote attackers to create arbitrary files by exploiting the writeManifest method in the CacheEntry class.
Who is impacted by CVE-2008-3112?
Users of outdated versions of Sun's Java software, specifically those running affected JDK and JRE versions, are at risk from CVE-2008-3112.