UTF-8 Encoding Vulnerability in Java Runtime Environment by Sun
CVE-2008-5351
Currently unrated
Summary
The Java Runtime Environment (JRE) in versions like JDK and JRE 6 Update 10 and earlier, along with JDK and JRE 5.0 Update 16 and earlier, contains a vulnerability related to the handling of UTF-8 encodings. This issue allows attackers to utilize non-standard UTF-8 encodings that are not in their 'shortest' form, effectively bypassing security mechanisms in other applications that depend on the shortest form for encoding validation. This vulnerability can lead to various security risks, as it compromises the integrity and reliability of data handling within the applications relying on the affected JRE versions.
References
Timeline
Vulnerability published
Vulnerability Reserved