Zero Day Initiative Advisory 08-080...

- AV AC AU C I A
发布: 2008-12-05
修订: 2025-04-13

A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sun Microsystems Java. User interaction is required in that a user must open a malicious file or visit a malicious web page. The specific flaw occurs within the Java AWT library. If a custom image model is used for the source 'Raster' during a conversion through a 'ConvolveOp' operation, the imaging library will calculate the size of the destination raster for the conversion incorrectly leading to a heap-based overflow. This can result in arbitrary code execution under the context of the current user.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息