You are here: Security Center > Mozilla Foundation Security Advisories > MFSA 2011-54

Mozilla Foundation Security Advisory 2011-54

Title: Potentially exploitable crash in the YARR regular expression library
Impact: Critical
Announced: December 20, 2011
Reporter: Aki Helin
Products: Firefox, Thunderbird, SeaMonkey

Fixed in: Firefox 9.0
  Thunderbird 9.0
  SeaMonkey 2.6

Description

Security researcher Aki Helin reported a crash in the YARR regular expression library that could be triggered by javascript in web content.

The YARR library was not used in older versions of the Mozilla browser engine. This vulnerability does not affect Firefox 3.6 or Thunderbird 3.1

References