Memory corruption due to multipart/x-mixed-replace images

Related Vulnerabilities: CVE-2011-2377  

Mozilla Foundation Security Advisory 2011-21

Memory corruption due to multipart/x-mixed-replace images

Announced
June 21, 2011
Reporter
Jordi Chancel
Impact
Critical
Products
Firefox, SeaMonkey, Thunderbird
Fixed in
  • Firefox 3.6.18
  • Firefox 5
  • SeaMonkey 2.2
  • Thunderbird 3.1.11

Description

Security researcher Jordi Chancel reported a crash on multipart/x-mixed-replace images due to memory corruption.

References