CVE-2008-5351
Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier accepts UTF-8 encodings that are not the "shortest" form, which makes it easier for attackers to bypass protection mechanisms for other applications that rely on shortest-form UTF-8 encodings.
- Affected products
- Hp-Ux, Jdk, Java Platform, Java Runtime Environment, Sdk
- Sun Jdk
- ≤ 5.0, 6
- Sun Jre
- ≤ 1.4.2_18, 5.0, 6, 1.4.2_1, 1.4.2_2, 1.4.2_3, 1.4.2_4, 1.4.2_5, 1.4.2_6, 1.4.2_7, 1.4.2_8, 1.4.2_9, 1.4.2_10, 1.4.2_11, 1.4.2_12, 1.4.2_13, 1.4.2_14, 1.4.2_15, 1.4.2_16, 1.4.2_17
- Sun Sdk
- ≤ 1.4.2_18, 1.4.2_1, 1.4.2_2, 1.4.2_3, 1.4.2_4, 1.4.2_5, 1.4.2_6, 1.4.2_7, 1.4.2_8, 1.4.2_9, 1.4.2_10, 1.4.2_11, 1.4.2_12, 1.4.2_13, 1.4.2_14, 1.4.2_15, 1.4.2_16, 1.4.2_17
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 3.4% (88th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2008-12-05
CVE-2008-5351 at NVD
1 known exploit for CVE-2008-5351
Proof-of-concept code and exploit modules indexed by Sploitus