CVE-2006-2426: Medium severity Java Development Kit (JDK) vulnerability
Sun Java Runtime Environment (JRE) 1.5.06 and earlier, JDK 1.5.06 and earlier, and SDK 1.5.06 and earlier allows remote attackers to cause a denial of service (disk consumption) by using the Font.createFont function to create temporary files of arbitrary size in the %temp% directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2426?
CVE-2006-2426 has a severity rating that indicates it can lead to a denial of service through disk consumption.
How do I fix CVE-2006-2426?
To fix CVE-2006-2426, upgrade to a newer version of the Sun Java Runtime Environment, JDK, or SDK that is not vulnerable.
What are the affected versions in CVE-2006-2426?
CVE-2006-2426 affects Sun Java Runtime Environment 1.5.0_6 and earlier, as well as JDK and SDK of the same version.
What type of vulnerability is CVE-2006-2426?
CVE-2006-2426 is classified as a denial of service vulnerability due to arbitrary disk space consumption.
Can CVE-2006-2426 be exploited remotely?
Yes, CVE-2006-2426 can be exploited remotely by attackers to create large temporary files that consume disk space.