CVE-2008-5355 DetailsDescription The "Java Update" feature for Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not verify the signature of the JRE that is downloaded, which allows remote attackers to execute arbitrary code via DNS man-in-the-middle attacks.
Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 SSVC
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration Affected Products Product Versions sun jdk <= 5.0
<= 6
5.0 update_1
5.0 update_10
5.0 update_11
5.0 update_12
5.0 update_13
5.0 update_14
5.0 update_15
5.0 update_2
5.0 update_3
5.0 update_4
5.0 update_5
5.0 update_6
5.0 update_7
5.0 update_8
5.0 update_9
6
6 update_1
6 update_2
6 update_3
6 update_4
6 update_5
6 update_6
6 update_7
6 update_8
6 update_9
Viewing 5 of 27 versions. View all CPE cpe:2.3:a:sun:jdk:*:update_16:*:*:*:*:*:* cpe:2.3:a:sun:jdk:*:update_10:*:*:*:*:*:* cpe:2.3:a:sun:jdk:5.0:update_1:*:*:*:*:*:* cpe:2.3:a:sun:jdk:5.0:update_10:*:*:*:*:*:* cpe:2.3:a:sun:jdk:5.0:update_11:*:*:*:*:*:* cpe:2.3:a:sun:jdk:5.0:update_12:*:*:*:*:*:* cpe:2.3:a:sun:jdk:5.0:update_13:*:*:*:*:*:* cpe:2.3:a:sun:jdk:5.0:update_14:*:*:*:*:*:* cpe:2.3:a:sun:jdk:5.0:update_15:*:*:*:*:*:* cpe:2.3:a:sun:jdk:5.0:update_2:*:*:*:*:*:* cpe:2.3:a:sun:jdk:5.0:update_3:*:*:*:*:*:* cpe:2.3:a:sun:jdk:5.0:update_4:*:*:*:*:*:* cpe:2.3:a:sun:jdk:5.0:update_5:*:*:*:*:*:* cpe:2.3:a:sun:jdk:5.0:update_6:*:*:*:*:*:* cpe:2.3:a:sun:jdk:5.0:update_7:*:*:*:*:*:* cpe:2.3:a:sun:jdk:5.0:update_8:*:*:*:*:*:* cpe:2.3:a:sun:jdk:5.0:update_9:*:*:*:*:*:* cpe:2.3:a:sun:jdk:6:*:*:*:*:*:*:* cpe:2.3:a:sun:jdk:6:update_1:*:*:*:*:*:* cpe:2.3:a:sun:jdk:6:update_2:*:*:*:*:*:* cpe:2.3:a:sun:jdk:6:update_3:*:*:*:*:*:* cpe:2.3:a:sun:jdk:6:update_4:*:*:*:*:*:* cpe:2.3:a:sun:jdk:6:update_5:*:*:*:*:*:* cpe:2.3:a:sun:jdk:6:update_6:*:*:*:*:*:* cpe:2.3:a:sun:jdk:6:update_7:*:*:*:*:*:* cpe:2.3:a:sun:jdk:6:update_8:*:*:*:*:*:* cpe:2.3:a:sun:jdk:6:update_9:*:*:*:*:*:* Remediation No remediation found in references. sun jre <= 1.4.2_18
<= 5.0
<= 6
1.4.2_1
1.4.2_2
1.4.2_3
1.4.2_4
1.4.2_5
1.4.2_6
1.4.2_7
1.4.2_8
1.4.2_9
1.4.2_10
1.4.2_11
1.4.2_12
1.4.2_13
1.4.2_14
1.4.2_15
1.4.2_16
1.4.2_17
5.0
5.0 update_1
5.0 update_10
5.0 update_11
5.0 update_12
5.0 update_13
5.0 update_14
5.0 update_15
5.0 update_2
5.0 update_3
5.0 update_4
5.0 update_5
5.0 update_6
5.0 update_7
5.0 update_8
5.0 update_9
6
6 update_1
6 update_2
6 update_3
6 update_4
6 update_5
6 update_6
6 update_7
6 update_8
6 update_9
Viewing 5 of 46 versions. View all CPE cpe:2.3:a:sun:jre:*:*:*:*:*:*:*:* cpe:2.3:a:sun:jre:*:update_16:*:*:*:*:*:* cpe:2.3:a:sun:jre:*:update_10:*:*:*:*:*:* cpe:2.3:a:sun:jre:1.4.2_1:*:*:*:*:*:*:* cpe:2.3:a:sun:jre:1.4.2_2:*:*:*:*:*:*:* cpe:2.3:a:sun:jre:1.4.2_3:*:*:*:*:*:*:* cpe:2.3:a:sun:jre:1.4.2_4:*:*:*:*:*:*:* cpe:2.3:a:sun:jre:1.4.2_5:*:*:*:*:*:*:* cpe:2.3:a:sun:jre:1.4.2_6:*:*:*:*:*:*:* cpe:2.3:a:sun:jre:1.4.2_7:*:*:*:*:*:*:* cpe:2.3:a:sun:jre:1.4.2_8:*:*:*:*:*:*:* cpe:2.3:a:sun:jre:1.4.2_9:*:*:*:*:*:*:* cpe:2.3:a:sun:jre:1.4.2_10:*:*:*:*:*:*:* cpe:2.3:a:sun:jre:1.4.2_11:*:*:*:*:*:*:* cpe:2.3:a:sun:jre:1.4.2_12:*:*:*:*:*:*:* cpe:2.3:a:sun:jre:1.4.2_13:*:*:*:*:*:*:* cpe:2.3:a:sun:jre:1.4.2_14:*:*:*:*:*:*:* cpe:2.3:a:sun:jre:1.4.2_15:*:*:*:*:*:*:* cpe:2.3:a:sun:jre:1.4.2_16:*:*:*:*:*:*:* cpe:2.3:a:sun:jre:1.4.2_17:*:*:*:*:*:*:* cpe:2.3:a:sun:jre:5.0:*:*:*:*:*:*:* cpe:2.3:a:sun:jre:5.0:update_1:*:*:*:*:*:* cpe:2.3:a:sun:jre:5.0:update_10:*:*:*:*:*:* cpe:2.3:a:sun:jre:5.0:update_11:*:*:*:*:*:* cpe:2.3:a:sun:jre:5.0:update_12:*:*:*:*:*:* cpe:2.3:a:sun:jre:5.0:update_13:*:*:*:*:*:* cpe:2.3:a:sun:jre:5.0:update_14:*:*:*:*:*:* cpe:2.3:a:sun:jre:5.0:update_15:*:*:*:*:*:* cpe:2.3:a:sun:jre:5.0:update_2:*:*:*:*:*:* cpe:2.3:a:sun:jre:5.0:update_3:*:*:*:*:*:* cpe:2.3:a:sun:jre:5.0:update_4:*:*:*:*:*:* cpe:2.3:a:sun:jre:5.0:update_5:*:*:*:*:*:* cpe:2.3:a:sun:jre:5.0:update_6:*:*:*:*:*:* cpe:2.3:a:sun:jre:5.0:update_7:*:*:*:*:*:* cpe:2.3:a:sun:jre:5.0:update_8:*:*:*:*:*:* cpe:2.3:a:sun:jre:5.0:update_9:*:*:*:*:*:* cpe:2.3:a:sun:jre:6:*:*:*:*:*:*:* cpe:2.3:a:sun:jre:6:update_1:*:*:*:*:*:* cpe:2.3:a:sun:jre:6:update_2:*:*:*:*:*:* cpe:2.3:a:sun:jre:6:update_3:*:*:*:*:*:* cpe:2.3:a:sun:jre:6:update_4:*:*:*:*:*:* cpe:2.3:a:sun:jre:6:update_5:*:*:*:*:*:* cpe:2.3:a:sun:jre:6:update_6:*:*:*:*:*:* cpe:2.3:a:sun:jre:6:update_7:*:*:*:*:*:* cpe:2.3:a:sun:jre:6:update_8:*:*:*:*:*:* cpe:2.3:a:sun:jre:6:update_9:*:*:*:*:*:* Remediation No remediation found in references. sun sdk <= 1.4.2_18
1.4.2_1
1.4.2_2
1.4.2_3
1.4.2_4
1.4.2_5
1.4.2_6
1.4.2_7
1.4.2_8
1.4.2_9
1.4.2_10
1.4.2_11
1.4.2_12
1.4.2_13
1.4.2_14
1.4.2_15
1.4.2_16
1.4.2_17
Viewing 5 of 18 versions. View all CPE cpe:2.3:a:sun:sdk:*:*:*:*:*:*:*:* cpe:2.3:a:sun:sdk:1.4.2_1:*:*:*:*:*:*:* cpe:2.3:a:sun:sdk:1.4.2_2:*:*:*:*:*:*:* cpe:2.3:a:sun:sdk:1.4.2_3:*:*:*:*:*:*:* cpe:2.3:a:sun:sdk:1.4.2_4:*:*:*:*:*:*:* cpe:2.3:a:sun:sdk:1.4.2_5:*:*:*:*:*:*:* cpe:2.3:a:sun:sdk:1.4.2_6:*:*:*:*:*:*:* cpe:2.3:a:sun:sdk:1.4.2_7:*:*:*:*:*:*:* cpe:2.3:a:sun:sdk:1.4.2_8:*:*:*:*:*:*:* cpe:2.3:a:sun:sdk:1.4.2_9:*:*:*:*:*:*:* cpe:2.3:a:sun:sdk:1.4.2_10:*:*:*:*:*:*:* cpe:2.3:a:sun:sdk:1.4.2_11:*:*:*:*:*:*:* cpe:2.3:a:sun:sdk:1.4.2_12:*:*:*:*:*:*:* cpe:2.3:a:sun:sdk:1.4.2_13:*:*:*:*:*:*:* cpe:2.3:a:sun:sdk:1.4.2_14:*:*:*:*:*:*:* cpe:2.3:a:sun:sdk:1.4.2_15:*:*:*:*:*:*:* cpe:2.3:a:sun:sdk:1.4.2_16:*:*:*:*:*:*:* cpe:2.3:a:sun:sdk:1.4.2_17:*:*:*:*:*:*:* Remediation No remediation found in references.
Change History 6 change records found show changes