Novell Home

CVE-2008-5356

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

CVE-2008-5356 at MITRE

Details

Heap-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file.
Novell Bugzilla entries: 456770,465624,471829,496004

SUSE Security Advisories:

Product(s) Fixed package version(s) References
SLES 11 DEBUGINFO
  • java-1_4_2-ibm-debuginfo >= 1.4.2_sr13-0.1.1
sle11-debuginfo. ppc
sle11-debuginfo. x86-64
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. ppc
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. ppc
sle11-debuginfo. x86
SAT Patch Nr: 735
SLE 11
  • java-1_4_2-ibm >= 1.4.2_sr13-0.1.1
  • java-1_4_2-ibm-devel >= 1.4.2_sr13-0.1.1
sle11-debuginfo. ppc
sle11-debuginfo. x86-64
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. ppc
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. ppc
sle11-debuginfo. x86
SAT Patch Nr: 735
SLE 11
  • java-1_4_2-ibm-devel >= 1.4.2_sr13-0.1.1
sle11-debuginfo. ppc
sle11-debuginfo. x86-64
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. ppc
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. ppc
sle11-debuginfo. x86
SAT Patch Nr: 735
SLES 11
  • java-1_4_2-ibm >= 1.4.2_sr13-0.1.1
  • java-1_4_2-ibm-jdbc >= 1.4.2_sr13-0.1.1
  • java-1_4_2-ibm-plugin >= 1.4.2_sr13-0.1.1
sle11-debuginfo. ppc
sle11-debuginfo. x86-64
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. ppc
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. ppc
sle11-debuginfo. x86
SAT Patch Nr: 735
SLES 11
  • java-1_4_2-ibm >= 1.4.2_sr13-0.1.1
sle11-debuginfo. ppc
sle11-debuginfo. x86-64
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. ppc
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. ppc
sle11-debuginfo. x86
SAT Patch Nr: 735
SUSE Linux Enterprise Desktop 10 SP2 for AMD64 and Intel EM64T
SUSE Linux Enterprise Desktop 10 SP2 for x86
  • java-1_4_2-sun >= 1.4.2.19-0.3
  • java-1_4_2-sun-alsa >= 1.4.2.19-0.3
  • java-1_4_2-sun-demo >= 1.4.2.19-0.3
  • java-1_4_2-sun-devel >= 1.4.2.19-0.3
  • java-1_4_2-sun-jdbc >= 1.4.2.19-0.3
  • java-1_4_2-sun-plugin >= 1.4.2.19-0.3
  • java-1_4_2-sun-src >= 1.4.2.19-0.3
sled10-sp2. x86-64
sles10-sp2. ia64
sled10-sp2. x86
sles10-sp2. x86-64
sles10-sp2. x86
ZYPP Patch Nr: 5852
SUSE Linux Enterprise Server 10 SP2 for AMD64 and Intel EM64T
SUSE Linux Enterprise Server 10 SP2 for x86
  • java-1_4_2-sun >= 1.4.2.19-0.3
  • java-1_4_2-sun-alsa >= 1.4.2.19-0.3
  • java-1_4_2-sun-devel >= 1.4.2.19-0.3
  • java-1_4_2-sun-jdbc >= 1.4.2.19-0.3
  • java-1_4_2-sun-plugin >= 1.4.2.19-0.3
sled10-sp2. x86-64
sles10-sp2. ia64
sled10-sp2. x86
sles10-sp2. x86-64
sles10-sp2. x86
ZYPP Patch Nr: 5852
SUSE Linux Enterprise Server 10 SP2 for IPF
  • java-1_4_2-sun >= 1.4.2.19-0.3
  • java-1_4_2-sun-devel >= 1.4.2.19-0.3
  • java-1_4_2-sun-jdbc >= 1.4.2.19-0.3
  • java-1_4_2-sun-plugin >= 1.4.2.19-0.3
sled10-sp2. x86-64
sles10-sp2. ia64
sled10-sp2. x86
sles10-sp2. x86-64
sles10-sp2. x86
ZYPP Patch Nr: 5852
SUSE CORE 9 for x86
  • IBMJava2-JRE >= 1.4.2-0.142
  • IBMJava2-SDK >= 1.4.2-0.142
sles9-sp3. x86
sles9-sp3. s390x
YOU Patch Nr: 12405
SUSE CORE 9 for IBM zSeries 64bit
  • IBMJava2-JRE >= 1.4.2-0.145
  • IBMJava2-SDK >= 1.4.2-0.145
sles9-sp3. x86
sles9-sp3. s390x
YOU Patch Nr: 12405
SLE 11
  • java-1_6_0-ibm >= 1.6.0-124.6.1
  • java-1_6_0-ibm-devel >= 1.6.0-124.6.1
  • java-1_6_0-ibm-fonts >= 1.6.0-124.6.1
sle11. s390x
sle11. x86-64
sle11. x86
sle11. x86-64
sle11. ppc
sle11. x86
sle11. ppc
sle11. s390x
SAT Patch Nr: 736
SLE 11
  • java-1_6_0-ibm-devel >= 1.6.0-124.6.1
sle11. s390x
sle11. x86-64
sle11. x86
sle11. x86-64
sle11. ppc
sle11. x86
sle11. ppc
sle11. s390x
SAT Patch Nr: 736
SLES 11
  • java-1_6_0-ibm >= 1.6.0-124.6.1
  • java-1_6_0-ibm-alsa >= 1.6.0-124.6.1
  • java-1_6_0-ibm-fonts >= 1.6.0-124.6.1
  • java-1_6_0-ibm-jdbc >= 1.6.0-124.6.1
  • java-1_6_0-ibm-plugin >= 1.6.0-124.6.1
sle11. s390x
sle11. x86-64
sle11. x86
sle11. x86-64
sle11. ppc
sle11. x86
sle11. ppc
sle11. s390x
SAT Patch Nr: 736
SLES 11
  • java-1_6_0-ibm >= 1.6.0-124.6.1
  • java-1_6_0-ibm-fonts >= 1.6.0-124.6.1
  • java-1_6_0-ibm-jdbc >= 1.6.0-124.6.1
sle11. s390x
sle11. x86-64
sle11. x86
sle11. x86-64
sle11. ppc
sle11. x86
sle11. ppc
sle11. s390x
SAT Patch Nr: 736
Novell Linux POS 9
Open Enterprise Server
SUSE CORE 9 for IBM POWER
SUSE CORE 9 for IBM S/390 31bit
SUSE CORE 9 for IBM zSeries 64bit
SUSE CORE 9 for x86
  • IBMJava5-JRE >= 1.5.0-0.57
  • IBMJava5-SDK >= 1.5.0-0.57
core9. x86
core9. s390
core9. x86-64
core9. ppc
sles9-nlpos. x86
core9. s390x
sles9-oes. x86
YOU Patch Nr: 12336
SUSE CORE 9 for AMD64 and Intel EM64T
  • IBMJava5-JRE >= 1.5.0-0.56
  • IBMJava5-SDK >= 1.5.0-0.56
core9. x86
core9. s390
core9. x86-64
core9. ppc
sles9-nlpos. x86
core9. s390x
sles9-oes. x86
YOU Patch Nr: 12336
SUSE Linux Enterprise Desktop 10 SP2 for x86
  • java-1_5_0-ibm >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-alsa >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-demo >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-devel >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-fonts >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-jdbc >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-plugin >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-src >= 1.5.0_sr9-2.4
sles10-sp2. ppc
sles10-sp2. x86
sles10-sp2. x86-64
sled10-sp2. x86-64
sles10-sp2. s390x
sled10-sp2. x86
ZYPP Patch Nr: 5960
SUSE Linux Enterprise Desktop 10 SP2 for AMD64 and Intel EM64T
  • java-1_5_0-ibm >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-32bit >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-alsa-32bit >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-demo >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-devel >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-devel-32bit >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-fonts >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-src >= 1.5.0_sr9-2.4
sles10-sp2. ppc
sles10-sp2. x86
sles10-sp2. x86-64
sled10-sp2. x86-64
sles10-sp2. s390x
sled10-sp2. x86
ZYPP Patch Nr: 5960
SUSE Linux Enterprise Server 10 SP2 for x86
  • java-1_5_0-ibm >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-alsa >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-devel >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-fonts >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-jdbc >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-plugin >= 1.5.0_sr9-2.4
sles10-sp2. ppc
sles10-sp2. x86
sles10-sp2. x86-64
sled10-sp2. x86-64
sles10-sp2. s390x
sled10-sp2. x86
ZYPP Patch Nr: 5960
SUSE Linux Enterprise Server 10 SP2 for IBM POWER
  • java-1_5_0-ibm >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-64bit >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-devel >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-fonts >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-jdbc >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-plugin >= 1.5.0_sr9-2.4
sles10-sp2. ppc
sles10-sp2. x86
sles10-sp2. x86-64
sled10-sp2. x86-64
sles10-sp2. s390x
sled10-sp2. x86
ZYPP Patch Nr: 5960
SUSE Linux Enterprise Server 10 SP2 for IBM zSeries 64bit
  • java-1_5_0-ibm >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-32bit >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-devel >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-devel-32bit >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-fonts >= 1.5.0_sr9-2.4
sles10-sp2. ppc
sles10-sp2. x86
sles10-sp2. x86-64
sled10-sp2. x86-64
sles10-sp2. s390x
sled10-sp2. x86
ZYPP Patch Nr: 5960
SUSE Linux Enterprise Server 10 SP2 for AMD64 and Intel EM64T
  • java-1_5_0-ibm >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-32bit >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-alsa-32bit >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-devel >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-devel-32bit >= 1.5.0_sr9-2.4
  • java-1_5_0-ibm-fonts >= 1.5.0_sr9-2.4
sles10-sp2. ppc
sles10-sp2. x86
sles10-sp2. x86-64
sled10-sp2. x86-64
sles10-sp2. s390x
sled10-sp2. x86
ZYPP Patch Nr: 5960
openSUSE 10.3
openSUSE 11.0
  • java-1_5_0-sun >= 1.5.0_update17-0.1
  • java-1_5_0-sun-alsa >= 1.5.0_update17-0.1
  • java-1_5_0-sun-demo >= 1.5.0_update17-0.1
  • java-1_5_0-sun-devel >= 1.5.0_update17-0.1
  • java-1_5_0-sun-jdbc >= 1.5.0_update17-0.1
  • java-1_5_0-sun-plugin >= 1.5.0_update17-0.1
  • java-1_5_0-sun-src >= 1.5.0_update17-0.1
ZYPP Patch Nr: 5875
SAT Patch Nr: 375
openSUSE 11.1
  • java-1_5_0-sun >= 1.5.0_update17-1.1
  • java-1_5_0-sun-alsa >= 1.5.0_update17-1.1
  • java-1_5_0-sun-devel >= 1.5.0_update17-1.1
  • java-1_5_0-sun-jdbc >= 1.5.0_update17-1.1
  • java-1_5_0-sun-plugin >= 1.5.0_update17-1.1
ZYPP Patch Nr: 5875
SAT Patch Nr: 375
Novell Linux POS 9
Open Enterprise Server
SUSE CORE 9 for x86
  • IBMJava2-JRE >= 1.4.2-0.133
  • IBMJava2-SDK >= 1.4.2-0.133
core9. s390
sles9-nlpos. x86
core9. ppc
core9. s390x
core9. x86-64
core9. ia64
core9. x86
sles9-oes. x86
YOU Patch Nr: 12387
SUSE CORE 9 for AMD64 and Intel EM64T
SUSE CORE 9 for IBM POWER
SUSE CORE 9 for IBM S/390 31bit
SUSE CORE 9 for IBM zSeries 64bit
SUSE CORE 9 for Itanium Processor Family
  • IBMJava2-JRE >= 1.4.2-0.139
  • IBMJava2-SDK >= 1.4.2-0.139
core9. s390
sles9-nlpos. x86
core9. ppc
core9. s390x
core9. x86-64
core9. ia64
core9. x86
sles9-oes. x86
YOU Patch Nr: 12387
openSUSE 11.0
  • java-1_6_0-openjdk-debuginfo >= 1.4_b14-24.2
  • java-1_6_0-openjdk-debugsource >= 1.4_b14-24.2
SAT Patch Nr: 578
openSUSE 11.0
  • java-1_6_0-openjdk >= 1.4_b14-24.2
  • java-1_6_0-openjdk-demo >= 1.4_b14-24.2
  • java-1_6_0-openjdk-devel >= 1.4_b14-24.2
  • java-1_6_0-openjdk-javadoc >= 1.4_b14-24.2
  • java-1_6_0-openjdk-plugin >= 1.4_b14-24.2
  • java-1_6_0-openjdk-src >= 1.4_b14-24.2
SAT Patch Nr: 578
openSUSE 11.1
  • java-1_6_0-openjdk-debuginfo >= 1.4_b14-24.2.1
  • java-1_6_0-openjdk-debugsource >= 1.4_b14-24.2.1
SAT Patch Nr: 578
openSUSE 11.1
  • java-1_6_0-openjdk >= 1.4_b14-24.2.1
  • java-1_6_0-openjdk-demo >= 1.4_b14-24.2.1
  • java-1_6_0-openjdk-devel >= 1.4_b14-24.2.1
  • java-1_6_0-openjdk-javadoc >= 1.4_b14-24.2.1
  • java-1_6_0-openjdk-plugin >= 1.4_b14-24.2.1
  • java-1_6_0-openjdk-src >= 1.4_b14-24.2.1
SAT Patch Nr: 578
openSUSE 10.3
  • java-1_6_0-sun >= 1.6.0.u11-0.1
  • java-1_6_0-sun-alsa >= 1.6.0.u11-0.1
  • java-1_6_0-sun-debuginfo >= 1.6.0.u11-0.1
  • java-1_6_0-sun-demo >= 1.6.0.u11-0.1
  • java-1_6_0-sun-devel >= 1.6.0.u11-0.1
  • java-1_6_0-sun-jdbc >= 1.6.0.u11-0.1
  • java-1_6_0-sun-plugin >= 1.6.0.u11-0.1
ZYPP Patch Nr: 5876
SAT Patch Nr: 376
openSUSE 11.0
  • java-1_6_0-sun >= 1.6.0.u11-0.1
  • java-1_6_0-sun-alsa >= 1.6.0.u11-0.1
  • java-1_6_0-sun-demo >= 1.6.0.u11-0.1
  • java-1_6_0-sun-devel >= 1.6.0.u11-0.1
  • java-1_6_0-sun-jdbc >= 1.6.0.u11-0.1
  • java-1_6_0-sun-plugin >= 1.6.0.u11-0.1
ZYPP Patch Nr: 5876
SAT Patch Nr: 376
openSUSE 11.1
  • java-1_6_0-sun >= 1.6.0.u11-1.1
  • java-1_6_0-sun-alsa >= 1.6.0.u11-1.1
  • java-1_6_0-sun-devel >= 1.6.0.u11-1.1
  • java-1_6_0-sun-jdbc >= 1.6.0.u11-1.1
  • java-1_6_0-sun-plugin >= 1.6.0.u11-1.1
ZYPP Patch Nr: 5876
SAT Patch Nr: 376
SUSE Linux Enterprise Server 10 SP1 for x86
  • java-1_4_2-ibm >= 1.4.2_sr13-0.2.2
  • java-1_4_2-ibm-devel >= 1.4.2_sr13-0.2.2
  • java-1_4_2-ibm-jdbc >= 1.4.2_sr13-0.2.2
  • java-1_4_2-ibm-plugin >= 1.4.2_sr13-0.2.2
sles10. x86
sles10. x86-64
sles10. s390x
ZYPP Patch Nr: 6202
SUSE Linux Enterprise Server 10 SP1 for AMD64 and Intel EM64T
SUSE Linux Enterprise Server 10 SP1 for IBM zSeries 64bit
  • java-1_4_2-ibm >= 1.4.2_sr13-0.2.2
  • java-1_4_2-ibm-devel >= 1.4.2_sr13-0.2.2
sles10. x86
sles10. x86-64
sles10. s390x
ZYPP Patch Nr: 6202
SLE SDK 10 SP2 for x86
SUSE Linux Enterprise Server 10 SP2 for x86
  • java-1_4_2-ibm >= 1.4.2_sr13-0.4
  • java-1_4_2-ibm-devel >= 1.4.2_sr13-0.4
  • java-1_4_2-ibm-jdbc >= 1.4.2_sr13-0.4
  • java-1_4_2-ibm-plugin >= 1.4.2_sr13-0.4
sles10-sp2-sdk. ppc
sles10-sp2. x86-64
sles10-sp2-sdk. ia64
sles10-sp2. ia64
sles10-sp2. x86
sles10-sp2-sdk. x86
sles10-sp2-sdk. s390x
sles10-sp2. s390x
sles10-sp2-sdk. x86-64
sles10-sp2. ppc
ZYPP Patch Nr: 6136
SLE SDK 10 SP2 for IBM iSeries and IBM pSeries
SUSE Linux Enterprise Server 10 SP2 for IBM POWER
  • java-1_4_2-ibm >= 1.4.2_sr13-0.4
  • java-1_4_2-ibm-devel >= 1.4.2_sr13-0.4
  • java-1_4_2-ibm-jdbc >= 1.4.2_sr13-0.4
sles10-sp2-sdk. ppc
sles10-sp2. x86-64
sles10-sp2-sdk. ia64
sles10-sp2. ia64
sles10-sp2. x86
sles10-sp2-sdk. x86
sles10-sp2-sdk. s390x
sles10-sp2. s390x
sles10-sp2-sdk. x86-64
sles10-sp2. ppc
ZYPP Patch Nr: 6136
SLE SDK 10 SP2 for IBM zSeries
SLE SDK 10 SP2 for IPF
SLE SDK 10 SP2 for X86-64
SUSE Linux Enterprise Server 10 SP2 for AMD64 and Intel EM64T
SUSE Linux Enterprise Server 10 SP2 for IBM zSeries 64bit
SUSE Linux Enterprise Server 10 SP2 for IPF
  • java-1_4_2-ibm >= 1.4.2_sr13-0.4
  • java-1_4_2-ibm-devel >= 1.4.2_sr13-0.4
sles10-sp2-sdk. ppc
sles10-sp2. x86-64
sles10-sp2-sdk. ia64
sles10-sp2. ia64
sles10-sp2. x86
sles10-sp2-sdk. x86
sles10-sp2-sdk. s390x
sles10-sp2. s390x
sles10-sp2-sdk. x86-64
sles10-sp2. ppc
ZYPP Patch Nr: 6136
Novell Linux Desktop 9 for x86
Novell Linux Desktop 9 for x86_64
Novell Linux POS 9
Open Enterprise Server
SUSE CORE 9 for AMD64 and Intel EM64T
SUSE CORE 9 for Itanium Processor Family
SUSE CORE 9 for x86
  • java2 >= 1.4.2-129.48
  • java2-jre >= 1.4.2-129.48
sles9-nlpos. x86
core9. x86-64
core9. x86
sles9-nld. x86
sles9-nld. x86-64
sles9-oes. x86
core9. ia64
YOU Patch Nr: 12321

Novell® Making IT Work As One

© 2009 Novell, Inc. All Rights Reserved.