CVE-2008-5352

UnknownEPSS 3.06%

Last modified

CVE-2008-5352 is a vulnerability of currently unknown severity. Integer overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack.dll) in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted applications and applets to gain privileges via a Pack200 compressed JAR file that triggers a heap-based buffer overflow.. EPSS estimates a 3.06% chance of exploitation in the next 30 days.

Description

Integer overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack.dll) in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted applications and applets to gain privileges via a Pack200 compressed JAR file that triggers a heap-based buffer overflow.

Metrics

EPSS Probability
3.06%

85.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
SunJdk<= 5.0Update 16
SunJdk<= 6Update 10
SunJdk5.0Update 1
SunJdk6
SunJre<= 5.0Update 16
SunJre<= 6Update 10
SunJre5.0
SunJre6

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2008-5352?
Integer overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack.dll) in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted applications and applets to gain privileges via a Pack200 compressed JAR file that triggers a heap-based buffer overflow.
How severe is CVE-2008-5352?
Severity scoring for CVE-2008-5352 is pending analysis. The EPSS model estimates a 3.06% probability of exploitation in the next 30 days.
How do I fix CVE-2008-5352?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2008-5352?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST