| Unspecified vulnerability in the 2D component in Oracle Java SE and
Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows
remote attackers to affect confidentiality, integrity, and
availability via unknown vectors. NOTE: the previous information was
obtained from the October 2010 CPU. Oracle has not commented on
claims from a reliable researcher that this is an integer overflow
that triggers memory corruption via large values in a subsample of a
JPEG image, related to JPEGImageWriter.writeImage in the imageio API.
|