Vulnerable Systems:
Oracle Java JDK and JRE 6 Update 25 and prior
Immune Systems:
Oracle Java JDK and JRE 6 Update 26
The vulnerability is caused by an integer overflow error in the Color Management Module (CMM) when processing a malformed "ncl2" tag within an ICC profile, which could be exploited by attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.
Patch Availability:
N/A
Workaround:
N/A
CVE Information:
N/A
Disclosure Timeline:
2010-12-21 - Vulnerability Discovered
2011-06-09 - Public disclosure