(1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.2_08, 1.4.2_09, and 1.5.0_05 and possibly other versions allow remote attackers to cause a denial of service (JVM unresponsive) via a crafted serialized object, such as a font object as demonstrated on JBoss.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jre | Sun | 1.4.2 (including) | 1.4.2 (including) |
Sdk | Sun | 1.4.2_08 (including) | 1.4.2_08 (including) |
Sdk | Sun | 1.4.2_09 (including) | 1.4.2_09 (including) |
Sdk | Sun | 1.5.0_05 (including) | 1.5.0_05 (including) |