Download Firefox

Firefox is no longer supported on Windows 8.1 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox is no longer supported on macOS 10.14 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox Privacy Notice

Mozilla Foundation Security Advisory 2011-54

Potentially exploitable crash in the YARR regular expression library

Announced
December 20, 2011
Reporter
Aki Helin
Impact
Critical
Products
Firefox, SeaMonkey, Thunderbird
Fixed in
  • Firefox 9
  • SeaMonkey 2.6
  • Thunderbird 9

Description

Security researcher Aki Helin reported a crash in the YARR regular expression library that could be triggered by javascript in web content.

The YARR library was not used in older versions of the Mozilla browser engine. This vulnerability does not affect Firefox 3.6 or Thunderbird 3.1

References