Created attachment 383222 [details] Source code reading ICC Profile file and calling filter method Sun Java 1.6 u 17 / IBM Java 1.6 SR 7 and java-1.6.0-openjdk-1.6.0.0-1.7.b09.el5 segfault on parsing forged ICC profiles. As java.awt.image.ColorConvertOp.filter is callable from untrusted applets, the vulnerable code could be a vector for privilege escalation attacks.
Created attachment 383223 [details] Color profile file