Out of bounds read in QCMS

Related Vulnerabilities: CVE-2012-1960  

Mozilla Foundation Security Advisory 2012-50

Out of bounds read in QCMS

Announced
July 17, 2012
Reporter
Tony Payne
Impact
Moderate
Products
Firefox, SeaMonkey, Thunderbird
Fixed in
  • Firefox 14
  • SeaMonkey 2.11
  • Thunderbird 14

Description

Google developer Tony Payne reported an out of bounds (OOB) read in QCMS, Mozilla’s color management library. With a carefully crafted color profile portions of a user's memory could be incorporated into a transformed image and possibly deciphered.

References