First published: Wed Jul 09 2008(Updated: )
Unspecified vulnerability in Sun Java Web Start in JDK and JRE 5.0 before Update 16 and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create or delete arbitrary files via an untrusted application, aka CR 6704077.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Java Development Kit (JDK) | <=5.0 | |
Java Development Kit (JDK) | =5.0-update_1 | |
Java Development Kit (JDK) | =5.0-update_10 | |
Java Development Kit (JDK) | =5.0-update_11 | |
Java Development Kit (JDK) | =5.0-update_12 | |
Java Development Kit (JDK) | =5.0-update_13 | |
Java Development Kit (JDK) | =5.0-update_14 | |
Java Development Kit (JDK) | =5.0-update_2 | |
Java Development Kit (JDK) | =5.0-update_3 | |
Java Development Kit (JDK) | =5.0-update_4 | |
Java Development Kit (JDK) | =5.0-update_5 | |
Java Development Kit (JDK) | =5.0-update_6 | |
Java Development Kit (JDK) | =5.0-update_7 | |
Java Development Kit (JDK) | =5.0-update_8 | |
Java Development Kit (JDK) | =5.0-update_9 | |
Sun Java Runtime Environment (JRE) | <=1.4.2_17 | |
Sun Java Runtime Environment (JRE) | <=5.0 | |
Sun Java Runtime Environment (JRE) | =1.4.2 | |
Sun Java Runtime Environment (JRE) | =1.4.2_01 | |
Sun Java Runtime Environment (JRE) | =1.4.2_02 | |
Sun Java Runtime Environment (JRE) | =1.4.2_03 | |
Sun Java Runtime Environment (JRE) | =1.4.2_04 | |
Sun Java Runtime Environment (JRE) | =1.4.2_05 | |
Sun Java Runtime Environment (JRE) | =1.4.2_06 | |
Sun Java Runtime Environment (JRE) | =1.4.2_07 | |
Sun Java Runtime Environment (JRE) | =1.4.2_8 | |
Sun Java Runtime Environment (JRE) | =1.4.2_9 | |
Sun Java Runtime Environment (JRE) | =1.4.2_10 | |
Sun Java Runtime Environment (JRE) | =1.4.2_11 | |
Sun Java Runtime Environment (JRE) | =1.4.2_12 | |
Sun Java Runtime Environment (JRE) | =1.4.2_13 | |
Sun Java Runtime Environment (JRE) | =1.4.2_14 | |
Sun Java Runtime Environment (JRE) | =1.4.2_15 | |
Sun Java Runtime Environment (JRE) | =1.4.2_16 | |
Sun Java Runtime Environment (JRE) | =5.0-update_1 | |
Sun Java Runtime Environment (JRE) | =5.0-update_10 | |
Sun Java Runtime Environment (JRE) | =5.0-update_11 | |
Sun Java Runtime Environment (JRE) | =5.0-update_12 | |
Sun Java Runtime Environment (JRE) | =5.0-update_13 | |
Sun Java Runtime Environment (JRE) | =5.0-update_14 | |
Sun Java Runtime Environment (JRE) | =5.0-update_2 | |
Sun Java Runtime Environment (JRE) | =5.0-update_3 | |
Sun Java Runtime Environment (JRE) | =5.0-update_4 | |
Sun Java Runtime Environment (JRE) | =5.0-update_5 | |
Sun Java Runtime Environment (JRE) | =5.0-update_6 | |
Sun Java Runtime Environment (JRE) | =5.0-update_7 | |
Sun Java Runtime Environment (JRE) | =5.0-update_8 | |
Sun Java Runtime Environment (JRE) | =5.0-update_9 | |
Java Development Kit (JDK) | =1.4.2 | |
Java Development Kit (JDK) | =1.4.2_01 | |
Java Development Kit (JDK) | =1.4.2_02 | |
Java Development Kit (JDK) | =1.4.2_03 | |
Java Development Kit (JDK) | =1.4.2_04 | |
Java Development Kit (JDK) | =1.4.2_05 | |
Java Development Kit (JDK) | =1.4.2_06 | |
Java Development Kit (JDK) | =1.4.2_07 | |
Java Development Kit (JDK) | =1.4.2_08 | |
Java Development Kit (JDK) | =1.4.2_09 | |
Java Development Kit (JDK) | =1.4.2_10 | |
Java Development Kit (JDK) | =1.4.2_11 | |
Java Development Kit (JDK) | =1.4.2_12 | |
Java Development Kit (JDK) | =1.4.2_13 | |
Java Development Kit (JDK) | =1.4.2_14 | |
Java Development Kit (JDK) | =1.4.2_15 | |
Java Development Kit (JDK) | =1.4.2_16 | |
Java Development Kit (JDK) | =1.4.2_17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3113 is considered to be of medium severity due to the potential for remote attackers to manipulate files.
To fix CVE-2008-3113, upgrade to a version of JDK or JRE that is 5.0 Update 16 or later, or 1.4.2_18 or later.
Affected software includes Sun JDK 5.0 prior to Update 16 and Sun JRE 1.4.2 prior to 1.4.2_18.
Yes, CVE-2008-3113 can be exploited remotely by untrusted applications to create or delete arbitrary files.
CVE-2008-3113 was disclosed in September 2008.