A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sun Microsystems Java. User interaction is required in that a user must open a malicious file or visit a malicious web page. The specific flaw occurs within the Java AWT library. If a custom image model is used for the source ‘Raster’ during a conversion through a ‘ConvolveOp’ operation, the imaging library will calculate the size of the destination raster for the conversion incorrectly leading to a heap-based overflow. This can result in arbitrary code execution under the context of the current user.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/72652/ZDI-08-080.txt
Source: https://packetstormsecurity.com/files/72652/Zero-Day-Initiative-Advisory-08-080.html