Bug 452658 (CVE-2008-3107)

Summary: CVE-2008-3107 JDK untrusted applet/application privilege escalation (6661918)
Product: [Other] Security Response Reporter: Marc Schoenefeld <mschoene>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aph, kreilly, rruss, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2010-12-23 21:33:24 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 454628, 454632, 454633    
Bug Blocks:    

Description Marc Schoenefeld 2008-06-24 12:04:48 UTC
From Sun pre-notification, 6/23/2008

A vulnerability in the Java Runtime Environment Virtual Machine may allow an 
untrusted applet or application to elevate its privileges. For example, an 
applet may grant itself permissions to read and write local files or execute 
local applications that are accessible to the user running the untrusted applet.

Comment 5 Fedora Update System 2008-07-09 19:17:09 UTC
java-1.6.0-openjdk-1.6.0.0-0.16.b09.fc9 has been submitted as an update for Fedora 9

Comment 6 Fedora Update System 2008-07-09 21:46:45 UTC
java-1.7.0-icedtea-1.7.0.0-0.20.b21.snapshot.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 8 Fedora Update System 2008-07-15 12:13:20 UTC
java-1.6.0-openjdk-1.6.0.0-0.16.b09.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 11 Vincent Danen 2010-12-23 21:33:24 UTC
This was addressed via:

RHEL Supplementary version 5 (java-1.6.0-sun) RHSA-2008:0594
Red Hat Enterprise Linux version 4 Extras (java-1.5.0-sun) RHSA-2008:0595
RHEL Supplementary version 5 (java-1.5.0-sun) RHSA-2008:0595
Red Hat Network Satellite Server 5.1 (RHEL v.4 AS) (java-1.5.0-sun)	RHSA-2008:0636