First published: Fri Dec 05 2008(Updated: )
Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to gain privileges to access local files or applications via unknown vectors, aka 6727081.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenJDK | =5.0-update_12 | |
Sun JRE | =6 | |
Sun JRE | =1.4.2_7 | |
OpenJDK | =5.0-update_15 | |
OpenJDK | <=5.0 | |
Sun JRE | =1.4.2_16 | |
OpenJDK | =5.0-update_3 | |
Sun JRE | =5.0-update_13 | |
Sun JRE | =5.0-update_1 | |
OpenJDK | =5.0-update_11 | |
Sun JRE | =1.4.2_4 | |
Sun SDK | =1.4.2_10 | |
Sun SDK | =1.4.2_12 | |
Sun JRE | =1.4.2_2 | |
OpenJDK | =6-update_6 | |
OpenJDK | =6-update_7 | |
OpenJDK | =5.0-update_8 | |
Sun JRE | =5.0-update_14 | |
Sun JRE | =6-update_3 | |
Sun JRE | =6-update_4 | |
Sun JRE | =5.0-update_12 | |
Sun SDK | =1.4.2_17 | |
Sun SDK | =1.4.2_14 | |
OpenJDK | =5.0-update_1 | |
Sun JRE | =1.4.2_15 | |
OpenJDK | =6-update_1 | |
OpenJDK | =6 | |
OpenJDK | =6-update_3 | |
Sun JRE | =1.4.2_13 | |
Sun JRE | =1.4.2_1 | |
OpenJDK | =6-update_9 | |
Sun SDK | =1.4.2_13 | |
Sun JRE | =1.4.2_8 | |
OpenJDK | =5.0-update_5 | |
Sun SDK | =1.4.2_6 | |
Sun JRE | =6-update_2 | |
Sun JRE | =5.0-update_4 | |
Sun JRE | =6-update_9 | |
OpenJDK | =6-update_4 | |
Sun SDK | <=1.4.2_18 | |
Sun JRE | <=1.4.2_18 | |
Sun SDK | =1.4.2_2 | |
Sun SDK | =1.4.2_5 | |
Sun JRE | =5.0-update_9 | |
Sun JRE | =1.4.2_12 | |
Sun SDK | =1.4.2_1 | |
Sun JRE | =5.0-update_8 | |
Sun JRE | <=6 | |
OpenJDK | <=6 | |
Sun JRE | =5.0-update_7 | |
OpenJDK | =5.0-update_6 | |
Sun JRE | =5.0-update_15 | |
Sun SDK | =1.4.2_4 | |
Sun JRE | =1.4.2_14 | |
Sun JRE | =6-update_5 | |
OpenJDK | =5.0-update_14 | |
OpenJDK | =6-update_8 | |
Sun JRE | =5.0-update_2 | |
Sun JRE | =1.4.2_10 | |
Sun JRE | <=5.0 | |
Sun JRE | =1.4.2_17 | |
OpenJDK | =6-update_2 | |
Sun SDK | =1.4.2_7 | |
Sun JRE | =6-update_7 | |
Sun JRE | =6-update_8 | |
Sun SDK | =1.4.2_8 | |
OpenJDK | =5.0-update_13 | |
Sun JRE | =5.0-update_5 | |
Sun JRE | =1.4.2_9 | |
Sun SDK | =1.4.2_16 | |
Sun SDK | =1.4.2_11 | |
Sun JRE | =5.0-update_6 | |
Sun JRE | =5.0-update_11 | |
Sun JRE | =1.4.2_11 | |
Sun SDK | =1.4.2_9 | |
Sun JRE | =6-update_1 | |
OpenJDK | =6-update_5 | |
OpenJDK | =5.0-update_10 | |
Sun SDK | =1.4.2_3 | |
Sun JRE | =1.4.2_3 | |
Sun JRE | =1.4.2_5 | |
OpenJDK | =5.0-update_2 | |
Sun JRE | =5.0 | |
Sun SDK | =1.4.2_15 | |
OpenJDK | =5.0-update_4 | |
OpenJDK | =5.0-update_9 | |
Sun JRE | =6-update_6 | |
Sun JRE | =5.0-update_3 | |
Sun JRE | =1.4.2_6 | |
Sun JRE | =5.0-update_10 | |
OpenJDK | =5.0-update_7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5340 has been rated as a critical security vulnerability due to the potential for untrusted applications to gain elevated privileges.
To fix CVE-2008-5340, upgrade to the latest version of the Java Development Kit (JDK) or Java Runtime Environment (JRE) that addresses this vulnerability.
Affected versions include Sun JDK and JRE 6 Update 10 and earlier, JDK and JRE 5.0 Update 16 and earlier, and JRE 1.4.2_18 and earlier.
CVE-2008-5340 could allow untrusted Java Web Start applications to access local files and applications without proper authorization.
Disabling Java Web Start or not running untrusted Java applications can mitigate the risk until a proper update is applied.