vendor:
Java Runtime Environment
by:
Unknown
7.5
CVSS
HIGH
Assertion Failure Denial of Service
399
CWE
Product Name: Java Runtime Environment
Affected Version From: 1.4.2001
Affected Version To: 1.4.2002
Patch Exists: YES
Related CWE: CVE-2004-1051
CPE: a:sun:java_runtime_environment:1.4.1
Platforms Tested:
2004
Sun Java Runtime Environment Font object assertion failure denial of service vulnerability
The Sun Java Runtime Environment Font object is vulnerable to an assertion failure denial of service vulnerability. This issue occurs when the process fails to handle exceptional conditions when processing font objects. An attacker can exploit this vulnerability by causing a vulnerable application, as well as all processes spawned from the application, to crash, denying service to legitimate users. Data loss may also occur.
Mitigation:
Apply the appropriate patches or updates provided by the vendor to address this vulnerability. Disable the Java plug-in in web browsers if it is not needed.