Vulnerable Systems:
* Sun Java JDK version 6 Update 18 and prior
* Sun Java JDK version 5.0 Update 23 and prior
* Sun Java JRE version 6 Update 18 and prior
* Sun Java JRE version 5.0 Update 23 and prior
* Sun Java JRE version 1.4.2_25 and prior
* Sun Java SDK version 1.4.2_25 and prior
The flaw is caused by an invalid pointer within the AWT (Abstract Windowing Toolkit) library when processing data passed to a specific function, which could be exploited by attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.
Disclosure Timeline:
2009-11-20 - Vendor notified
2009-11-24 - Vendor response
2010-01-09 - Status update received
2010-03-03 - Status update received
2010-03-31 - Coordinated public Disclosure