Memory corruption while profiling using Firebug

Related Vulnerabilities: CVE-2011-3650  

Mozilla Foundation Security Advisory 2011-49

Memory corruption while profiling using Firebug

Announced
November 8, 2011
Reporter
Marc Schoenefeld
Impact
Critical
Products
Firefox, SeaMonkey, Thunderbird
Fixed in
  • Firefox 3.6.24
  • Firefox 8
  • SeaMonkey 2.5
  • Thunderbird 3.1.16
  • Thunderbird 8

Description

Marc Schoenefeld reported a crash when using Firebug to profile a JavaScript file with many functions. It may be possible to trigger this crash without the use of debugging APIs, and if so this could be exploitable.

References