{"cves":[{"id":"CVE-2008-5370","published":"2008-12-08T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\npvpgn-support-installer in pvpgn 1.8.1 allows local users to overwrite\narbitrary files via a symlink attack on the /tmp/pvpgn-support-1.0.tar.gz\ntemporary file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5370"],"bugs":[""],"patches":{"pvpgn":[]},"tags":{},"packages":[{"name":"pvpgn","source":"https://ubuntu.com/security/cve?package=pvpgn","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pvpgn","debian":"https://tracker.debian.org/pkg/pvpgn","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.8.1-2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.8.1-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5369","published":"2008-12-08T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nnoip2 in noip2 2.1.7 allows local users to overwrite arbitrary files via a\nsymlink attack on the /tmp/noip2 temporary file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5369"],"bugs":[""],"patches":{"no-ip":[]},"tags":{},"packages":[{"name":"no-ip","source":"https://ubuntu.com/security/cve?package=no-ip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=no-ip","debian":"https://tracker.debian.org/pkg/no-ip","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.1.9-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"2.1.9-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5368","published":"2008-12-08T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmuttprint in muttprint 0.72d allows local users to overwrite arbitrary\nfiles via a symlink attack on the /tmp/muttprint.log temporary file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5368"],"bugs":[""],"patches":{"muttprint":[]},"tags":{},"packages":[{"name":"muttprint","source":"https://ubuntu.com/security/cve?package=muttprint","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=muttprint","debian":"https://tracker.debian.org/pkg/muttprint","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"0.72d-10","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.72d-10","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5367","published":"2008-12-08T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nip-up in ppp-udeb 2.4.4rel on Debian GNU/Linux allows local users to\noverwrite arbitrary files via a symlink attack on the /tmp/resolv.conf.tmp\ntemporary file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5367"],"bugs":[""],"patches":{"ppp":[]},"tags":{},"packages":[{"name":"ppp","source":"https://ubuntu.com/security/cve?package=ppp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ppp","debian":"https://tracker.debian.org/pkg/ppp","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5366","published":"2008-12-08T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe postinst script in ppp 2.4.4rel on Debian GNU/Linux allows local users\nto overwrite arbitrary files via a symlink attack on the (1)\n/tmp/probe-finished or (2) /tmp/ppp-errors temporary file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5366"],"bugs":[""],"patches":{"ppp":[]},"tags":{},"packages":[{"name":"ppp","source":"https://ubuntu.com/security/cve?package=ppp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ppp","debian":"https://tracker.debian.org/pkg/ppp","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5363","published":"2008-12-08T11:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ActionScript 2 virtual machine in Adobe Flash Player 10.x before\n10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not\nvalidate character elements during retrieval from the dictionary data\nstructure, which allows remote attackers to cause a denial of service (NULL\npointer dereference and application crash) via a crafted PDF file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5363"],"bugs":[""],"patches":{"flashplugin-nonfree":[]},"tags":{},"packages":[{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5362","published":"2008-12-08T11:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe DefineConstantPool action in the ActionScript 2 virtual machine in\nAdobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and\nAdobe AIR before 1.5, accepts an untrusted input value for a \"constant\ncount,\" which allows remote attackers to read sensitive data from process\nmemory via a crafted PDF file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5362"],"bugs":[""],"patches":{"flashplugin-nonfree":[]},"tags":{},"packages":[{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5361","published":"2008-12-08T11:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ActionScript 2 virtual machine in Adobe Flash Player 10.x before\n10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not\nverify a member element's size when performing (1) DefineConstantPool, (2)\nActionJump, (3) ActionPush, (4) ActionTry, and unspecified other actions,\nwhich allows remote attackers to read sensitive data from process memory\nvia a crafted PDF file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5361"],"bugs":[""],"patches":{"flashplugin-nonfree":[]},"tags":{},"packages":[{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5357","published":"2008-12-05T11:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6\nUpdate 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE\n1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow\nremote attackers to execute arbitrary code via a crafted TrueType font\nfile, which triggers a heap-based buffer overflow.","ubuntu_description":"","notes":[{"author":"kees","note":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-244987-1\n6733336\nvulnerable source not included in the open source JDK"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5357"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"6b14-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"6b14-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.5.0-19-0ubuntu0.8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.5.0-19-0ubuntu0.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6-17-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6-14-0ubuntu1.8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6-16-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5356","published":"2008-12-05T11:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK\nand JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and\nSDK and JRE 1.4.2_18 and earlier might allow remote attackers to execute\narbitrary code via a crafted TrueType font file.","ubuntu_description":"","notes":[{"author":"kees","note":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-244987-1\n6751322\nvulnerable source not included in the open source JDK"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5356"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"6b14-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"6b14-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.5.0-19-0ubuntu0.8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.5.0-19-0ubuntu0.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6-17-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6-14-0ubuntu1.8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6-16-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5355","published":"2008-12-05T11:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe \"Java Update\" feature for Java Runtime Environment (JRE) for Sun JDK\nand JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and\nSDK and JRE 1.4.2_18 and earlier does not verify the signature of the JRE\nthat is downloaded, which allows remote attackers to execute arbitrary code\nvia DNS man-in-the-middle attacks.","ubuntu_description":"","notes":[{"author":"kees","note":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-244989-1\n6728071\ninternal Java Updates are disabled on Ubuntu"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5355"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-2086","published":"2008-12-05T02:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSun Java Web Start and Java Plug-in for JDK and JRE 6 Update 10 and\nearlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18\nand earlier allow remote attackers to execute arbitrary code via a crafted\njnlp file that modifies the (1) java.home, (2) java.ext.dirs, or (3)\nuser.home System Properties, aka \"Java Web Start File Inclusion\" and CR\n6694892.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://sunsolve.sun.com/search/document.do?assetkey=1-26-244988-1","https://www.cve.org/CVERecord?id=CVE-2008-2086"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"java":[]},"tags":{},"packages":[{"name":"java","source":"https://ubuntu.com/security/cve?package=java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=java","debian":"https://tracker.debian.org/pkg/java","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"Web Start only","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"Web Start only","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"Web Start only","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"Web Start only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"1.5.0-19-0ubuntu0.8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.5.0-17-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.0-17","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6-17-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6-14-0ubuntu1.8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"6-11-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"6-11-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6-11","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-2379","published":"2008-12-05T00:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in SquirrelMail before 1.4.17\nallows remote attackers to inject arbitrary web script or HTML via a\ncrafted hyperlink in an HTML part of an e-mail message.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-2379"],"bugs":[""],"patches":{"squirrelmail":[]},"tags":{},"packages":[{"name":"squirrelmail","source":"https://ubuntu.com/security/cve?package=squirrelmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squirrelmail","debian":"https://tracker.debian.org/pkg/squirrelmail","statuses":[{"release_codename":"dapper","status":"released","description":"2:1.4.6-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2:1.4.10a-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2:1.4.13-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2:1.4.15-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.17","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5360","published":"2008-12-05T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nJava Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier;\nJDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier;\nand SDK and JRE 1.3.1_23 and earlier creates temporary files with\npredictable file names, which allows attackers to write malicious JAR files\nvia unknown vectors.","ubuntu_description":"","notes":[{"author":"kees","note":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-244986-1\n6721753"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-713-1","https://www.cve.org/CVERecord?id=CVE-2008-5360"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b11-2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"6b14-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"6b14-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.5.0-19-0ubuntu0.8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.5.0-19-0ubuntu0.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6-17-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6-14-0ubuntu1.8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6-16-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-713-1"],"notices":[{"id":"USN-713-1","title":"openjdk-6 vulnerabilities","summary":"openjdk-6 vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-01-27T22:18:48.536233","description":"It was discovered that Java did not correctly handle untrusted applets.\nIf a user were tricked into running a malicious applet, a remote attacker\ncould gain user privileges, or list directory contents. (CVE-2008-5347,\nCVE-2008-5350)\n\nIt was discovered that Kerberos authentication and RSA public key\nprocessing were not correctly handled in Java. A remote attacker\ncould exploit these flaws to cause a denial of service. (CVE-2008-5348,\nCVE-2008-5349)\n\nIt was discovered that Java accepted UTF-8 encodings that might be\nhandled incorrectly by certain applications. A remote attacker could\nbypass string filters, possible leading to other exploits. (CVE-2008-5351)\n\nOverflows were discovered in Java JAR processing. If a user or\nautomated system were tricked into processing a malicious JAR file,\na remote attacker could crash the application, leading to a denial of\nservice. (CVE-2008-5352, CVE-2008-5354)\n\nIt was discovered that Java calendar objects were not unserialized safely.\nIf a user or automated system were tricked into processing a specially\ncrafted calendar object, a remote attacker could execute arbitrary code\nwith user privileges. (CVE-2008-5353)\n\nIt was discovered that the Java image handling code could lead to memory\ncorruption. If a user or automated system were tricked into processing\na specially crafted image, a remote attacker could crash the application,\nleading to a denial of service. (CVE-2008-5358, CVE-2008-5359)\n\nIt was discovered that temporary files created by Java had predictable\nnames. If a user or automated system were tricked into processing a\nspecially crafted JAR file, a remote attacker could overwrite sensitive\ninformation. (CVE-2008-5360)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.1","description":"","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"openjdk-6-jre-lib","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"openjdk-6-jdk","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"}]},"type":"USN","cves_ids":["CVE-2008-5352","CVE-2008-5360","CVE-2008-5348","CVE-2008-5353","CVE-2008-5350","CVE-2008-5351","CVE-2008-5347","CVE-2008-5359","CVE-2008-5354","CVE-2008-5349","CVE-2008-5358"]}]},{"id":"CVE-2008-5359","published":"2008-12-05T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6\nUpdate 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE\n1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow\nremote attackers to execute arbitrary code, related to a ConvolveOp\noperation in the Java AWT library.","ubuntu_description":"","notes":[{"author":"kees","note":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-244987-1\n6726779"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-713-1","https://www.cve.org/CVERecord?id=CVE-2008-5359"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b11-2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"6b14-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"6b14-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.5.0-19-0ubuntu0.8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.5.0-19-0ubuntu0.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6-17-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6-14-0ubuntu1.8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6-16-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-713-1"],"notices":[{"id":"USN-713-1","title":"openjdk-6 vulnerabilities","summary":"openjdk-6 vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-01-27T22:18:48.536233","description":"It was discovered that Java did not correctly handle untrusted applets.\nIf a user were tricked into running a malicious applet, a remote attacker\ncould gain user privileges, or list directory contents. (CVE-2008-5347,\nCVE-2008-5350)\n\nIt was discovered that Kerberos authentication and RSA public key\nprocessing were not correctly handled in Java. A remote attacker\ncould exploit these flaws to cause a denial of service. (CVE-2008-5348,\nCVE-2008-5349)\n\nIt was discovered that Java accepted UTF-8 encodings that might be\nhandled incorrectly by certain applications. A remote attacker could\nbypass string filters, possible leading to other exploits. (CVE-2008-5351)\n\nOverflows were discovered in Java JAR processing. If a user or\nautomated system were tricked into processing a malicious JAR file,\na remote attacker could crash the application, leading to a denial of\nservice. (CVE-2008-5352, CVE-2008-5354)\n\nIt was discovered that Java calendar objects were not unserialized safely.\nIf a user or automated system were tricked into processing a specially\ncrafted calendar object, a remote attacker could execute arbitrary code\nwith user privileges. (CVE-2008-5353)\n\nIt was discovered that the Java image handling code could lead to memory\ncorruption. If a user or automated system were tricked into processing\na specially crafted image, a remote attacker could crash the application,\nleading to a denial of service. (CVE-2008-5358, CVE-2008-5359)\n\nIt was discovered that temporary files created by Java had predictable\nnames. If a user or automated system were tricked into processing a\nspecially crafted JAR file, a remote attacker could overwrite sensitive\ninformation. (CVE-2008-5360)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.1","description":"","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"openjdk-6-jre-lib","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"openjdk-6-jdk","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"}]},"type":"USN","cves_ids":["CVE-2008-5352","CVE-2008-5360","CVE-2008-5348","CVE-2008-5353","CVE-2008-5350","CVE-2008-5351","CVE-2008-5347","CVE-2008-5359","CVE-2008-5354","CVE-2008-5349","CVE-2008-5358"]}]},{"id":"CVE-2008-5358","published":"2008-12-05T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nJava Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier\nmight allow remote attackers to execute arbitrary code via a crafted GIF\nfile that triggers memory corruption during display of the splash screen,\npossibly related to splashscreen.dll.","ubuntu_description":"","notes":[{"author":"kees","note":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-244987-1\n6766136"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-713-1","https://www.cve.org/CVERecord?id=CVE-2008-5358"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b11-2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"6b14-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"6b14-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.5.0-19-0ubuntu0.8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.5.0-19-0ubuntu0.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6-17-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6-14-0ubuntu1.8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6-16-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-713-1"],"notices":[{"id":"USN-713-1","title":"openjdk-6 vulnerabilities","summary":"openjdk-6 vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-01-27T22:18:48.536233","description":"It was discovered that Java did not correctly handle untrusted applets.\nIf a user were tricked into running a malicious applet, a remote attacker\ncould gain user privileges, or list directory contents. (CVE-2008-5347,\nCVE-2008-5350)\n\nIt was discovered that Kerberos authentication and RSA public key\nprocessing were not correctly handled in Java. A remote attacker\ncould exploit these flaws to cause a denial of service. (CVE-2008-5348,\nCVE-2008-5349)\n\nIt was discovered that Java accepted UTF-8 encodings that might be\nhandled incorrectly by certain applications. A remote attacker could\nbypass string filters, possible leading to other exploits. (CVE-2008-5351)\n\nOverflows were discovered in Java JAR processing. If a user or\nautomated system were tricked into processing a malicious JAR file,\na remote attacker could crash the application, leading to a denial of\nservice. (CVE-2008-5352, CVE-2008-5354)\n\nIt was discovered that Java calendar objects were not unserialized safely.\nIf a user or automated system were tricked into processing a specially\ncrafted calendar object, a remote attacker could execute arbitrary code\nwith user privileges. (CVE-2008-5353)\n\nIt was discovered that the Java image handling code could lead to memory\ncorruption. If a user or automated system were tricked into processing\na specially crafted image, a remote attacker could crash the application,\nleading to a denial of service. (CVE-2008-5358, CVE-2008-5359)\n\nIt was discovered that temporary files created by Java had predictable\nnames. If a user or automated system were tricked into processing a\nspecially crafted JAR file, a remote attacker could overwrite sensitive\ninformation. (CVE-2008-5360)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.1","description":"","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"openjdk-6-jre-lib","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"openjdk-6-jdk","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"}]},"type":"USN","cves_ids":["CVE-2008-5352","CVE-2008-5360","CVE-2008-5348","CVE-2008-5353","CVE-2008-5350","CVE-2008-5351","CVE-2008-5347","CVE-2008-5359","CVE-2008-5354","CVE-2008-5349","CVE-2008-5358"]}]},{"id":"CVE-2008-5354","published":"2008-12-05T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK\nand JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and\nSDK and JRE 1.4.2_18 and earlier allows locally-launched and possibly\nremote untrusted Java applications to execute arbitrary code via a JAR file\nwith a long Main-Class manifest entry.","ubuntu_description":"","notes":[{"author":"kees","note":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-244990-1\n6733959"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-713-1","https://www.cve.org/CVERecord?id=CVE-2008-5354"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b11-2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"6b14-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"6b14-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.5.0-19-0ubuntu0.8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.5.0-19-0ubuntu0.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6-17-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6-14-0ubuntu1.8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6-16-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-713-1"],"notices":[{"id":"USN-713-1","title":"openjdk-6 vulnerabilities","summary":"openjdk-6 vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-01-27T22:18:48.536233","description":"It was discovered that Java did not correctly handle untrusted applets.\nIf a user were tricked into running a malicious applet, a remote attacker\ncould gain user privileges, or list directory contents. (CVE-2008-5347,\nCVE-2008-5350)\n\nIt was discovered that Kerberos authentication and RSA public key\nprocessing were not correctly handled in Java. A remote attacker\ncould exploit these flaws to cause a denial of service. (CVE-2008-5348,\nCVE-2008-5349)\n\nIt was discovered that Java accepted UTF-8 encodings that might be\nhandled incorrectly by certain applications. A remote attacker could\nbypass string filters, possible leading to other exploits. (CVE-2008-5351)\n\nOverflows were discovered in Java JAR processing. If a user or\nautomated system were tricked into processing a malicious JAR file,\na remote attacker could crash the application, leading to a denial of\nservice. (CVE-2008-5352, CVE-2008-5354)\n\nIt was discovered that Java calendar objects were not unserialized safely.\nIf a user or automated system were tricked into processing a specially\ncrafted calendar object, a remote attacker could execute arbitrary code\nwith user privileges. (CVE-2008-5353)\n\nIt was discovered that the Java image handling code could lead to memory\ncorruption. If a user or automated system were tricked into processing\na specially crafted image, a remote attacker could crash the application,\nleading to a denial of service. (CVE-2008-5358, CVE-2008-5359)\n\nIt was discovered that temporary files created by Java had predictable\nnames. If a user or automated system were tricked into processing a\nspecially crafted JAR file, a remote attacker could overwrite sensitive\ninformation. (CVE-2008-5360)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.1","description":"","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"openjdk-6-jre-lib","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"openjdk-6-jdk","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"}]},"type":"USN","cves_ids":["CVE-2008-5352","CVE-2008-5360","CVE-2008-5348","CVE-2008-5353","CVE-2008-5350","CVE-2008-5351","CVE-2008-5347","CVE-2008-5359","CVE-2008-5354","CVE-2008-5349","CVE-2008-5358"]}]},{"id":"CVE-2008-5353","published":"2008-12-05T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and\nearlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18\nand earlier does not properly enforce context of ZoneInfo objects during\ndeserialization, which allows remote attackers to run untrusted applets and\napplications in a privileged context, as demonstrated by \"deserializing\nCalendar objects\".","ubuntu_description":"","notes":[{"author":"kees","note":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-244991-1\n6734167"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-713-1","https://www.cve.org/CVERecord?id=CVE-2008-5353"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b11-2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"6b14-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"6b14-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.5.0-19-0ubuntu0.8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.5.0-19-0ubuntu0.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6-17-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6-14-0ubuntu1.8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6-16-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-713-1"],"notices":[{"id":"USN-713-1","title":"openjdk-6 vulnerabilities","summary":"openjdk-6 vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-01-27T22:18:48.536233","description":"It was discovered that Java did not correctly handle untrusted applets.\nIf a user were tricked into running a malicious applet, a remote attacker\ncould gain user privileges, or list directory contents. (CVE-2008-5347,\nCVE-2008-5350)\n\nIt was discovered that Kerberos authentication and RSA public key\nprocessing were not correctly handled in Java. A remote attacker\ncould exploit these flaws to cause a denial of service. (CVE-2008-5348,\nCVE-2008-5349)\n\nIt was discovered that Java accepted UTF-8 encodings that might be\nhandled incorrectly by certain applications. A remote attacker could\nbypass string filters, possible leading to other exploits. (CVE-2008-5351)\n\nOverflows were discovered in Java JAR processing. If a user or\nautomated system were tricked into processing a malicious JAR file,\na remote attacker could crash the application, leading to a denial of\nservice. (CVE-2008-5352, CVE-2008-5354)\n\nIt was discovered that Java calendar objects were not unserialized safely.\nIf a user or automated system were tricked into processing a specially\ncrafted calendar object, a remote attacker could execute arbitrary code\nwith user privileges. (CVE-2008-5353)\n\nIt was discovered that the Java image handling code could lead to memory\ncorruption. If a user or automated system were tricked into processing\na specially crafted image, a remote attacker could crash the application,\nleading to a denial of service. (CVE-2008-5358, CVE-2008-5359)\n\nIt was discovered that temporary files created by Java had predictable\nnames. If a user or automated system were tricked into processing a\nspecially crafted JAR file, a remote attacker could overwrite sensitive\ninformation. (CVE-2008-5360)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.1","description":"","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"openjdk-6-jre-lib","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"openjdk-6-jdk","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"}]},"type":"USN","cves_ids":["CVE-2008-5352","CVE-2008-5360","CVE-2008-5348","CVE-2008-5353","CVE-2008-5350","CVE-2008-5351","CVE-2008-5347","CVE-2008-5359","CVE-2008-5354","CVE-2008-5349","CVE-2008-5358"]}]},{"id":"CVE-2008-5352","published":"2008-12-05T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the JAR unpacking utility (unpack200) in the unpack\nlibrary (unpack.dll) in Java Runtime Environment (JRE) for Sun JDK and JRE\n6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows\nuntrusted applications and applets to gain privileges via a Pack200\ncompressed JAR file that triggers a heap-based buffer overflow.","ubuntu_description":"","notes":[{"author":"kees","note":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-244992-1\n6755943"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-713-1","https://www.cve.org/CVERecord?id=CVE-2008-5352"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b11-2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"6b14-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"6b14-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.5.0-19-0ubuntu0.8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.5.0-19-0ubuntu0.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6-17-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6-14-0ubuntu1.8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6-16-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-713-1"],"notices":[{"id":"USN-713-1","title":"openjdk-6 vulnerabilities","summary":"openjdk-6 vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-01-27T22:18:48.536233","description":"It was discovered that Java did not correctly handle untrusted applets.\nIf a user were tricked into running a malicious applet, a remote attacker\ncould gain user privileges, or list directory contents. (CVE-2008-5347,\nCVE-2008-5350)\n\nIt was discovered that Kerberos authentication and RSA public key\nprocessing were not correctly handled in Java. A remote attacker\ncould exploit these flaws to cause a denial of service. (CVE-2008-5348,\nCVE-2008-5349)\n\nIt was discovered that Java accepted UTF-8 encodings that might be\nhandled incorrectly by certain applications. A remote attacker could\nbypass string filters, possible leading to other exploits. (CVE-2008-5351)\n\nOverflows were discovered in Java JAR processing. If a user or\nautomated system were tricked into processing a malicious JAR file,\na remote attacker could crash the application, leading to a denial of\nservice. (CVE-2008-5352, CVE-2008-5354)\n\nIt was discovered that Java calendar objects were not unserialized safely.\nIf a user or automated system were tricked into processing a specially\ncrafted calendar object, a remote attacker could execute arbitrary code\nwith user privileges. (CVE-2008-5353)\n\nIt was discovered that the Java image handling code could lead to memory\ncorruption. If a user or automated system were tricked into processing\na specially crafted image, a remote attacker could crash the application,\nleading to a denial of service. (CVE-2008-5358, CVE-2008-5359)\n\nIt was discovered that temporary files created by Java had predictable\nnames. If a user or automated system were tricked into processing a\nspecially crafted JAR file, a remote attacker could overwrite sensitive\ninformation. (CVE-2008-5360)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.1","description":"","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"openjdk-6-jre-lib","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"openjdk-6-jdk","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"}]},"type":"USN","cves_ids":["CVE-2008-5352","CVE-2008-5360","CVE-2008-5348","CVE-2008-5353","CVE-2008-5350","CVE-2008-5351","CVE-2008-5347","CVE-2008-5359","CVE-2008-5354","CVE-2008-5349","CVE-2008-5358"]}]},{"id":"CVE-2008-5351","published":"2008-12-05T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nJava Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier;\nJDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier\naccepts UTF-8 encodings that are not the \"shortest\" form, which makes it\neasier for attackers to bypass protection mechanisms for other applications\nthat rely on shortest-form UTF-8 encodings.","ubuntu_description":"","notes":[{"author":"kees","note":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-245246-1\n4486841"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-713-1","https://www.cve.org/CVERecord?id=CVE-2008-5351"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6b11-2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6b12-0ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"6b14-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"6b14-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.5.0-22-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.5.0-19-0ubuntu0.8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.5.0-19-0ubuntu0.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6-17-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"6-14-0ubuntu1.8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6-16-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6-15-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-713-1"],"notices":[{"id":"USN-713-1","title":"openjdk-6 vulnerabilities","summary":"openjdk-6 vulnerabilities","instructions":"After a standard system upgrade you need to restart any Java applications\nto effect the necessary changes.\n","references":[],"published":"2009-01-27T22:18:48.536233","description":"It was discovered that Java did not correctly handle untrusted applets.\nIf a user were tricked into running a malicious applet, a remote attacker\ncould gain user privileges, or list directory contents. (CVE-2008-5347,\nCVE-2008-5350)\n\nIt was discovered that Kerberos authentication and RSA public key\nprocessing were not correctly handled in Java. A remote attacker\ncould exploit these flaws to cause a denial of service. (CVE-2008-5348,\nCVE-2008-5349)\n\nIt was discovered that Java accepted UTF-8 encodings that might be\nhandled incorrectly by certain applications. A remote attacker could\nbypass string filters, possible leading to other exploits. (CVE-2008-5351)\n\nOverflows were discovered in Java JAR processing. If a user or\nautomated system were tricked into processing a malicious JAR file,\na remote attacker could crash the application, leading to a denial of\nservice. (CVE-2008-5352, CVE-2008-5354)\n\nIt was discovered that Java calendar objects were not unserialized safely.\nIf a user or automated system were tricked into processing a specially\ncrafted calendar object, a remote attacker could execute arbitrary code\nwith user privileges. (CVE-2008-5353)\n\nIt was discovered that the Java image handling code could lead to memory\ncorruption. If a user or automated system were tricked into processing\na specially crafted image, a remote attacker could crash the application,\nleading to a denial of service. (CVE-2008-5358, CVE-2008-5359)\n\nIt was discovered that temporary files created by Java had predictable\nnames. If a user or automated system were tricked into processing a\nspecially crafted JAR file, a remote attacker could overwrite sensitive\ninformation. (CVE-2008-5360)\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"openjdk-6","version":"6b12-0ubuntu6.1","description":"","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"openjdk-6-jre-lib","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"icedtea6-plugin","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"openjdk-6-jdk","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"},{"name":"openjdk-6-jre","version":"6b12-0ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b12-0ubuntu6.1"}]},"type":"USN","cves_ids":["CVE-2008-5352","CVE-2008-5360","CVE-2008-5348","CVE-2008-5353","CVE-2008-5350","CVE-2008-5351","CVE-2008-5347","CVE-2008-5359","CVE-2008-5354","CVE-2008-5349","CVE-2008-5358"]}]}],"offset":74640,"limit":20,"total_results":79316}