.:[ packet storm ]:.
                           
honesty is the best policy
honesty is the best policy

 ///  File Name:ZDI-08-080.txt
Description:
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sun Microsystems Java. User interaction is required in that a user must open a malicious file or visit a malicious web page. The specific flaw occurs within the Java AWT library. If a custom image model is used for the source 'Raster' during a conversion through a 'ConvolveOp' operation, the imaging library will calculate the size of the destination raster for the conversion incorrectly leading to a heap-based overflow. This can result in arbitrary code execution under the context of the current user.
Author:Damian Put
Homepage:http://www.zerodayinitiative.com/
File Size:3498
Last Modified:Dec 4 21:29:55 2008
MD5 Checksum:6200c629b04c2740d64b04f0879bbc55

 .:. Back