First published: Fri Dec 05 2008(Updated: )
Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier might allow remote attackers to execute arbitrary code via a crafted GIF file that triggers memory corruption during display of the splash screen, possibly related to splashscreen.dll.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun JRE | =6 | |
Sun JDK | =6-update_6 | |
Sun JDK | =6-update_7 | |
Sun JRE | =6-update_3 | |
Sun JRE | =6-update_4 | |
Sun JDK | =6-update_1 | |
Sun JDK | =6 | |
Sun JDK | =6-update_3 | |
Sun JRE | =6-update_2 | |
Sun JDK | =6-update_4 | |
Sun JRE | <=6 | |
Sun JDK | <=6 | |
Sun JRE | =6-update_5 | |
Sun JDK | =6-update_8 | |
Sun JDK | =6-update_2 | |
Sun JRE | =6-update_7 | |
Sun JRE | =6-update_8 | |
Sun JRE | =6-update_1 | |
Sun JDK | =6-update_5 | |
Sun JRE | =6-update_6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5358 is considered a critical vulnerability due to the potential for remote code execution.
To fix CVE-2008-5358, you should update your Java Runtime Environment (JRE) or Java Development Kit (JDK) to a version later than 6 Update 10.
CVE-2008-5358 affects Java Runtime Environment (JRE) and Java Development Kit (JDK) versions 6 Update 10 and earlier.
CVE-2008-5358 enables remote attackers to execute arbitrary code via a crafted GIF file.
CVE-2008-5358 is potentially related to the splashscreen.dll file in the Java Runtime Environment.