NGSSoftware Insight Security Research Advisory – It is possible to cause the Java Virtual Machine to overwrite an arbitrary memory location with an arbitrary value (repeatedly and in a stable manner) when parsing a malformed TrueType font. JDK and JRE versions 5.0 Update 9 and below as well as SDK and JRE versions 1.4.2_14 and below are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/60521/NGS00419.txt
Source: https://packetstormsecurity.com/files/60521/NGS00419.txt.html