Out of Memory crash when parsing GIF format images

Related Vulnerabilities: CVE-2016-1933  

Mozilla Foundation Security Advisory 2016-02

Out of Memory crash when parsing GIF format images

Announced
January 26, 2016
Reporter
Gustavo Grieco
Impact
Moderate
Products
Firefox
Fixed in
  • Firefox 44

Description

Security researcher Gustavo Grieco reported an out of memory crash when loading maliciously crafted GIF format images. Investigation of the issue determined that the root cause was an error in image parsing code during deinterlacing, leading to a potential integer overflow.

References