First published: Fri Dec 05 2008(Updated: )
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote attackers to run untrusted applets and applications in a privileged context, as demonstrated by "deserializing Calendar objects".
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenJDK | =5.0-update_12 | |
Sun JRE | =6 | |
Sun JRE | =1.4.2_7 | |
OpenJDK | =5.0-update_15 | |
OpenJDK | <=5.0 | |
Sun JRE | =1.4.2_16 | |
OpenJDK | =5.0-update_3 | |
Sun JRE | =5.0-update_13 | |
Sun JRE | =5.0-update_1 | |
OpenJDK | =5.0-update_11 | |
Sun JRE | =1.4.2_4 | |
Sun SDK | =1.4.2_10 | |
Sun SDK | =1.4.2_12 | |
Sun JRE | =1.4.2_2 | |
OpenJDK | =6-update_6 | |
OpenJDK | =6-update_7 | |
OpenJDK | =5.0-update_8 | |
Sun JRE | =5.0-update_14 | |
Sun JRE | =6-update_3 | |
Sun JRE | =6-update_4 | |
Sun JRE | =5.0-update_12 | |
Sun SDK | =1.4.2_17 | |
Sun SDK | =1.4.2_14 | |
OpenJDK | =5.0-update_1 | |
Sun JRE | =1.4.2_15 | |
OpenJDK | =6-update_1 | |
OpenJDK | =6 | |
OpenJDK | =6-update_3 | |
Sun JRE | =1.4.2_13 | |
Sun JRE | =1.4.2_1 | |
OpenJDK | =6-update_9 | |
Sun SDK | =1.4.2_13 | |
Sun JRE | =1.4.2_8 | |
OpenJDK | =5.0-update_5 | |
Sun SDK | =1.4.2_6 | |
Sun JRE | =6-update_2 | |
Sun JRE | =5.0-update_4 | |
Sun JRE | =6-update_9 | |
OpenJDK | =6-update_4 | |
Sun SDK | <=1.4.2_18 | |
Sun JRE | <=1.4.2_18 | |
Sun SDK | =1.4.2_2 | |
Sun SDK | =1.4.2_5 | |
Sun JRE | =5.0-update_9 | |
Sun JRE | =1.4.2_12 | |
Sun SDK | =1.4.2_1 | |
Sun JRE | =5.0-update_8 | |
Sun JRE | <=6 | |
OpenJDK | <=6 | |
Sun JRE | =5.0-update_7 | |
OpenJDK | =5.0-update_6 | |
Sun JRE | =5.0-update_15 | |
Sun SDK | =1.4.2_4 | |
Sun JRE | =1.4.2_14 | |
Sun JRE | =6-update_5 | |
OpenJDK | =5.0-update_14 | |
OpenJDK | =6-update_8 | |
Sun JRE | =5.0-update_2 | |
Sun JRE | =1.4.2_10 | |
Sun JRE | <=5.0 | |
Sun JRE | =1.4.2_17 | |
OpenJDK | =6-update_2 | |
Sun SDK | =1.4.2_7 | |
Sun JRE | =6-update_7 | |
Sun JRE | =6-update_8 | |
Sun SDK | =1.4.2_8 | |
OpenJDK | =5.0-update_13 | |
Sun JRE | =5.0-update_5 | |
Sun JRE | =1.4.2_9 | |
Sun SDK | =1.4.2_16 | |
Sun SDK | =1.4.2_11 | |
Sun JRE | =5.0-update_6 | |
Sun JRE | =5.0-update_11 | |
Sun JRE | =1.4.2_11 | |
Sun SDK | =1.4.2_9 | |
Sun JRE | =6-update_1 | |
OpenJDK | =6-update_5 | |
OpenJDK | =5.0-update_10 | |
Sun SDK | =1.4.2_3 | |
Sun JRE | =1.4.2_3 | |
Sun JRE | =1.4.2_5 | |
OpenJDK | =5.0-update_2 | |
Sun JRE | =5.0 | |
Sun SDK | =1.4.2_15 | |
OpenJDK | =5.0-update_4 | |
OpenJDK | =5.0-update_9 | |
Sun JRE | =6-update_6 | |
Sun JRE | =5.0-update_3 | |
Sun JRE | =1.4.2_6 | |
Sun JRE | =5.0-update_10 | |
OpenJDK | =5.0-update_7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5353 is rated as a critical vulnerability, allowing remote execution of untrusted applets.
To fix CVE-2008-5353, update your Java Runtime Environment to the latest version provided by Sun Microsystems.
CVE-2008-5353 affects Sun JDK and JRE versions 6 Update 10 and earlier, as well as JDK and JRE 5.0 Update 16 and earlier.
The impact of CVE-2008-5353 includes the potential execution of arbitrary code by an attacker through the exploitation of deserialization of ZoneInfo objects.
Users and organizations running vulnerable versions of the Java Runtime Environment are at risk of exploitation due to CVE-2008-5353.