PublicDate: 2008-07-09 23:41:00 UTC Candidate: CVE-2008-3107 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3107 Description: Unspecified vulnerability in the Virtual Machine in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_sun-java5: upstream_sun-java5: released (1.5.0-16-1) dapper_sun-java5: ignored (reached end-of-life) feisty_sun-java5: needs-triage (reached end-of-life) gutsy_sun-java5: needs-triage (reached end-of-life) hardy_sun-java5: released (1.5.0-22-0ubuntu0.8.04) intrepid_sun-java5: not-affected (1.5.0-16-2ubuntu1) jaunty_sun-java5: not-affected (1.5.0-16-2ubuntu1) karmic_sun-java5: DNE devel_sun-java5: DNE Patches_sun-java6: upstream_sun-java6: released (6-07-1) dapper_sun-java6: DNE feisty_sun-java6: needs-triage (reached end-of-life) gutsy_sun-java6: needs-triage (reached end-of-life) hardy_sun-java6: released (6-17-0ubuntu1.8.04) intrepid_sun-java6: not-affected (6-07-3ubuntu1) jaunty_sun-java6: not-affected (6-07-3ubuntu1) karmic_sun-java6: not-affected (6-07-3ubuntu1) devel_sun-java6: not-affected (6-07-3ubuntu1) Patches_openjdk-6: upstream_openjdk-6: released (6b11) dapper_openjdk-6: DNE feisty_openjdk-6: DNE gutsy_openjdk-6: DNE hardy_openjdk-6: released (6b11-2ubuntu2.1) intrepid_openjdk-6: released (6b11-1) jaunty_openjdk-6: released (6b11-1) karmic_openjdk-6: released (6b11-1) devel_openjdk-6: released (6b11-1)