Java.Deserializing.Calendar.Privilege

NameJava.Deserializing.Calendar.Privilege.Elevation
Last Updated DateJul 23, 2009
Release DateMay 29, 2009
SeverityCritical
ImpactPrivilege escalation: Remote attackers can leverage their privilege on vulnerable systems.
DescriptionThis indicates an attack attempt against a privilege-escalation vulnerability in the Jave Runtime Environment (JRE).

The vulnerability is caused by an error when the affected software handles processes related to deserializing calendar objects. It allows a remote attacker to escalate privileges such as reading, writing and running local files or applications.
Affected ProductsJRE for Sun JDK and JRE 6 Update 10 and earlier
JDK and JRE 5.0 Update 16 and earlier
JRE 1.4.2_18 and earlier
Recommended ActionsApply the latest update from the vendor:
http://sunsolve.sun.com/search/document.do?assetkey=1-66-244991-1
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-5353
Reference/shttp://www.securityfocus.com/bid/32608 (BugTraq)
http://sunsolve.sun.com/search/document.do?assetkey=1-66-244991-1
http://www.us-cert.gov/cas/techalerts/TA08-340A.html
Reference: VID-17418