PDA

View Full Version : iDefense Labs: Sun Java JRE TrueType Font Parsing Heap Overflow Vulnerability


kjkoster
04-12-2008, 22:44
Dear All,

iDefense Labs is reporting that there is a vulnerability in Java's font handling (http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=757), possibly allowing attackers to run code under the user's privileges.

No CVE number yet.

A patch (http://onesearch.sun.com/onesearch/index.jsp?qt=Bug%206751322&charset=UTF-8) has been released by Sun.

Kees Jan