This script is Copyright (C) 2012-2014 Tenable Network Security, Inc.
The remote Scientific Linux host is missing one or more security
Flaws in the JRE allowed an untrusted application or applet to elevate
its privileges. This could be exploited by a remote attacker to access
local files or execute local applications accessible to the user
running the JRE (CVE-2008-1185, CVE-2008-1186)
A flaw was found in the Java XSLT processing classes. An untrusted
application or applet could cause a denial of service, or execute
arbitrary code with the permissions of the user running the JRE.
Several buffer overflow flaws were found in Java Web Start (JWS). An
untrusted JNLP application could access local files or execute local
applications accessible to the user running the JRE. (CVE-2008-1188,
CVE-2008-1189, CVE-2008-1190, CVE-2008-1191, CVE-2008-1196)
A flaw was found in the Java Plug-in. A remote attacker could bypass
the same origin policy, executing arbitrary code with the permissions
of the user running the JRE. (CVE-2008-1192)
A flaw was found in the JRE image parsing libraries. An untrusted
application or applet could cause a denial of service, or possible
execute arbitrary code with the permissions of the user running the
A flaw was found in the JRE color management library. An untrusted
application or applet could trigger a denial of service (JVM crash).
connections by the use of Java APIs. A remote attacker could use these
flaws to access local network services. (CVE-2008-1195)
A vulnerability was found in the Java Management Extensions (JMX)
management agent, when local monitoring is enabled. This allowed
remote attackers to perform illegal operations. (CVE-2008-3103)
Multiple vulnerabilities with unsigned applets were reported. A remote
attacker could misuse an unsigned applet to connect to localhost
services running on the host running the applet. (CVE-2008-3104)
A Java Runtime Environment (JRE) vulnerability could be triggered by
an untrusted application or applet. A remote attacker could grant an
untrusted applet extended privileges such as reading and writing local
files, or executing local programs. (CVE-2008-3107)
Several buffer overflow vulnerabilities in Java Web Start were
reported. These vulnerabilities may allow an untrusted Java Web Start
application to elevate its privileges and thereby grant itself
permission to read and/or write local files, as well as to execute
local applications accessible to the user running the untrusted
Two file processing vulnerabilities in Java Web Start were found. A
remote attacker, by means of an untrusted Java Web Start application,
was able to create or delete arbitrary files with the permissions of
the user running the untrusted application. (CVE-2008-3112,
A vulnerability in Java Web Start when processing untrusted
applications was reported. An attacker was able to acquire sensitive
information, such as the cache location. (CVE-2008-3114)
See also :
Update the affected java-1.5.0-sun-compat and / or jdk packages.
Risk factor :
Critical / CVSS Base Score : 10.0
Public Exploit Available : true
Family: Scientific Linux Local Security Checks
Nessus Plugin ID: 60440 ()
CVE ID: CVE-2008-1185CVE-2008-1186CVE-2008-1187CVE-2008-1188CVE-2008-1189CVE-2008-1190CVE-2008-1191CVE-2008-1192CVE-2008-1193CVE-2008-1194CVE-2008-1195CVE-2008-1196CVE-2008-3103CVE-2008-3104CVE-2008-3107CVE-2008-3111CVE-2008-3112CVE-2008-3113CVE-2008-3114
Upgrade to Nessus Professional today!
Start your free Nessus Cloud trial now!
Begin Free Trial
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.