CVE-2008-5343: Critical severity java development kit (jdk) vulnerability
Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.218 and earlier allows remote attackers to make unauthorized network connections and hijack HTTP sessions via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR" and CR 6707535.
Other sources
Name: CVE-2008-5343 Status: Candidate URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5343 Reference: SUNALERT:244988 Reference: URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-244988-1
Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.218 and earlier allows "hidden code" to make unauthorized network connections and "hijack HTTP sessions using cookies stored in the browser" via unknown vectors.
— Red Hat
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2008-5343?
CVE-2008-5343 is considered a medium severity vulnerability that allows unauthorized network connections and HTTP session hijacking.
How do I fix CVE-2008-5343?
To fix CVE-2008-5343, you should upgrade your Java versions to the latest updates provided by Sun or Oracle.
What versions are affected by CVE-2008-5343?
CVE-2008-5343 affects Sun JDK and JRE versions 6 Update 10 and earlier, 5.0 Update 16 and earlier, and 1.4.2_18 and earlier.
What types of attacks can CVE-2008-5343 facilitate?
CVE-2008-5343 can facilitate remote attacks that enable unauthorized network connections and HTTP session hijacking.
Is there a patch available for CVE-2008-5343?
Yes, patches are available for CVE-2008-5343 through updates provided by Sun or Oracle for affected Java versions.