CVE-2008-5360
Sun JDK and JRE - Arbitrary JAR File Write via Predictable Temporary File Names
Title source: llmDescription
Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier creates temporary files with predictable file names, which allows attackers to write malicious JAR files via unknown vectors.
References (39)
Core 39
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/32608
Mailing List, Third Party Advisory vendor-advisory
x_refsource_hp
http://marc.info/?l=bugtraq&m=126583436323697&w=2
Third Party Advisory x_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2008-484.htm
Mailing List, Third Party Advisory vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00004.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/34259
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0672
Third Party Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2008-1018.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/33015
Third Party Advisory x_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2009-012.htm
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/34889
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/34233
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200911-02.xml
Patch, Vendor Advisory vendor-advisory
x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-244986-1
Third Party Advisory x_refsource_confirm
http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2009/03/024431-01.pdf
Mailing List, Third Party Advisory vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00009.html
Mailing List, Third Party Advisory vendor-advisory
x_refsource_hp
http://marc.info/?l=bugtraq&m=123678756409861&w=2
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/38539
Third Party Advisory vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6596
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/34972
Third Party Advisory vendor-advisory
x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2009-0466.html
Mailing List, Third Party Advisory vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/35065
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/33528
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1021316
Third Party Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2008-1025.html
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3339
Mailing List, Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/47045
Third Party Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-0445.html
Third Party Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-0016.html
Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA08-340A.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/33709
Third Party Advisory x_refsource_confirm
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=829914&poid=
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/34605
Mailing List, Third Party Advisory vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
Third Party Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-0015.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/33187
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/32991
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/37386
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/33710
Scores
EPSS
0.0374
EPSS Percentile
88.2%
Details
Status
published
Products (34)
sun/jdk
1.5.0 (11 CPE variants)
sun/jdk
1.6.0 (7 CPE variants)
sun/jre
1.3.1
sun/jre
1.3.1_2
sun/jre
1.3.1_03
sun/jre
1.3.1_04
sun/jre
1.3.1_05
sun/jre
1.3.1_06
sun/jre
1.3.1_07
sun/jre
1.3.1_08
... and 24 more
Published
Dec 05, 2008
Tracked Since
Feb 18, 2026