Mozilla Foundation Security Advisory 2015-38
Memory corruption crashes in Off Main Thread Compositing
- Announced
- March 31, 2015
- Reporter
- Abhishek Arya
- Impact
- Critical
- Products
- Firefox, Firefox OS, SeaMonkey
- Fixed in
-
- Firefox 37
- Firefox OS 2.2
- SeaMonkey 2.35
Description
Security researcher Abhishek Arya (Inferno) of the Google Chrome Security Team used the Address Sanitizer tool to discover two memory corruption crashes during 2D graphics rendering due to problems in Off Main Thread Compositing. These crashes are potentially exploitable.