Format string vulnerability in Kaffe OpenVM 1.0.6 and earlier allows local users to execute arbitrary code, when a java.lang.NoClassDefFoundError is thrown, via format specifiers in the forName attribute.
Link | Tags |
---|---|
http://www.iss.net/security_center/static/8399.php | vdb entry |
http://www.securityfocus.com/bid/4249 | vdb entry |
http://cert.uni-stuttgart.de/archive/vuln-dev/2002/03/msg00050.html | mailing list exploit |