Crash scaling <video> to extreme sizes

Related Vulnerabilities: CVE-2011-3665  

Mozilla Foundation Security Advisory 2011-58

Crash scaling <video> to extreme sizes

Announced
December 20, 2011
Reporter
sczimmer
Impact
Critical
Products
Firefox, SeaMonkey, Thunderbird
Fixed in
  • Firefox 9
  • SeaMonkey 2.6
  • Thunderbird 9

Description

sczimmer reported a crash when scaling an OGG <video> element to extreme sizes.

Firefox 3.6 is not affected by this vulnerability

References