---
title: "CVE-2008-3106\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2008-3106?format=md
keywords: index, follow
---

# CVE-2008-3106

Publication date 9 July 2008

Last updated 24 July 2024

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Unspecified vulnerability in Sun Java Runtime Environment (JRE) in JDK and
JRE 6 Update 6 and earlier and JDK and JRE 5.0 Update 15 and earlier allows
remote attackers to access URLs via unknown vectors involving processing of
XML data by an untrusted (1) application or (2) applet, a different
vulnerability than CVE-2008-3105.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| openjdk-6 | 9.10 karmic | Fixed 6b11-1 |
| 9.04 jaunty | Fixed 6b11-1 |
| 8.10 intrepid | Fixed 6b11-1 |
| 8.04 LTS hardy | Fixed 6b11-2ubuntu2.1 |
| 7.10 gutsy | Not in release |
| 7.04 feisty | Not in release |
| 6.06 LTS dapper | Not in release |
| sun-java5 | 9.10 karmic | Not in release |
| 9.04 jaunty | Not affected |
| 8.10 intrepid | Not affected |
| 8.04 LTS hardy | Fixed 1.5.0-22-0ubuntu0.8.04 |
| 7.10 gutsy | Ignored end of life, was needs-triage |
| 7.04 feisty | Ignored end of life, was needs-triage |
| 6.06 LTS dapper | Ignored end of life |
| sun-java6 | 9.10 karmic | Not affected |
| 9.04 jaunty | Not affected |
| 8.10 intrepid | Not affected |
| 8.04 LTS hardy | Fixed 6-17-0ubuntu1.8.04 |
| 7.10 gutsy | Ignored end of life, was needs-triage |
| 7.04 feisty | Ignored end of life, was needs-triage |
| 6.06 LTS dapper | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3106)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2008-3106)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2008-3106)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2008-3106)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2008-3106>
