CVE-2008-5352

Priority
Medium
Description
Integer overflow in the JAR unpacking utility (unpack200) in the unpack
library (unpack.dll) in Java Runtime Environment (JRE) for Sun JDK and JRE
6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows
untrusted applications and applets to gain privileges via a Pack200
compressed JAR file that triggers a heap-based buffer overflow.
References
Notes
 kees> http://sunsolve.sun.com/search/document.do?assetkey=1-26-244992-1
 kees> 6755943
Assigned-to
kees
Package
Upstream:needs-triage
Package
Upstream:needs-triage
Package
Upstream:needs-triage
More Information

Valid XHTML 1.0 Strict

Updated: 2015-07-29 20:34:21 UTC (commit 9756)