The class file parser in IBM Java 1.4.2 SR13 FP9 allows remote authenticated users to cause a denial of service (memory consumption or an infinite loop) via a crafted attribute length field in a class file, related to validation of a length field at the wrong time, a different vulnerability than CVE-2011-0311.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/69641 | vdb entry |
https://www-304.ibm.com/support/docview.wss?uid=isg1PM42551 | vendor advisory |
http://www.redhat.com/support/errata/RHSA-2011-1265.html | vendor advisory |