Mozilla Foundation Security Advisory 2009-10
Upgrade PNG library to fix memory safety hazards
- Announced
- March 4, 2009
- Reporter
- Tavis Ormandy
- Impact
- Critical
- Products
- Firefox, SeaMonkey, Thunderbird
- Fixed in
-
- Firefox 3.0.7
- SeaMonkey 1.1.15
- Thunderbird 2.0.0.21
Description
Google security researcher Tavis Ormandy reported
several memory safety hazards to the libpng
project, an
external library used by Mozilla to render PNG images. These vulnerabilities
could be used by a malicious website to crash a victim's browser and
potentially execute arbitrary code on their computer. libpng
was upgraded to version 1.2.35 which containis fixes for these flaws.