If a certain type of message, containing a specially-crafted Unicode data packet, is sent to the JDENET Service, the JDENET Kernel executes a system call, using a user-provided value as the time parameter. This causes the service to stop responding for a period of time.
Further technical details about this issue are not disclosed at this moment with the purpose of providing enough time to affected customers to patch their systems and protect against the exploitation of the described vulnerability.
Disclosure Timeline:
2010-09-20: Vulnerability information to Oracle.
2010-09-21: Oracle confirms reception of vulnerability submission.
2010-09-24: Oracle states vulnerability is under investigation.
2010-10-07: Oracle confirms vulnerability.
2011-04-19: Oracle releases fixes in CPU.
2011-04-27: Security advisory released.