CVE-2008-2086
Sun JDK and JRE < 6 Update 11 - Remote Code Execution via Crafted JNLP File
Title source: llmDescription
Sun Java Web Start and Java Plug-in for JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allow remote attackers to execute arbitrary code via a crafted jnlp file that modifies the (1) java.home, (2) java.ext.dirs, or (3) user.home System Properties, aka "Java Web Start File Inclusion" and CR 6694892.
References (37)
Core 37
Core References
Mailing List vendor-advisory
x_refsource_hp
http://marc.info/?l=bugtraq&m=126583436323697&w=2
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2008-1018.html
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00004.html
Vendor Advisory x_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2009-012.htm
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0672
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/32620
Third Party Advisory third-party-advisory
x_refsource_sreason
http://securityreason.com/securityalert/4693
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/33015
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/34889
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/34233
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200911-02.xml
Various Sources x_refsource_confirm
http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2009/03/024431-01.pdf
Vendor Advisory x_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2008-486.htm
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5601
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00009.html
Mailing List vendor-advisory
x_refsource_hp
http://marc.info/?l=bugtraq&m=123678756409861&w=2
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/38539
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/50510
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/35065
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/33528
Various Sources x_refsource_misc
http://www.vsecurity.com/bulletins/advisories/2008/JWS-props.txt
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0424
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1021318
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2008-1025.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-0445.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-0016.html
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/498907/100/0/threaded
US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA08-340A.html
Various Sources x_refsource_confirm
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=829914&poid=
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/34605
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-0015.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/32991
Mailing List vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2009/Feb/msg00003.html
Vendor Advisory vendor-advisory
x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-244988-1
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/37386
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/33710
Scores
EPSS
0.2855
EPSS Percentile
96.6%
Details
CWE
CWE-94
Status
published
Products (22)
sun/jdk
5.0 update_1 (15 CPE variants)
sun/jdk
6 (10 CPE variants)
sun/jdk
< 5.0
sun/jdk
< 6
sun/jre
1.4.2_1
sun/jre
1.4.2_2
sun/jre
1.4.2_3
sun/jre
1.4.2_4
sun/jre
1.4.2_5
sun/jre
1.4.2_6
... and 12 more
Published
Dec 05, 2008
Tracked Since
Feb 18, 2026