You are here: Security Center > Mozilla Foundation Security Advisories > MFSA 2012-25

Mozilla Foundation Security Advisory 2012-25

Title: Potential memory corruption during font rendering using cairo-dwrite
Impact: Critical
Announced: April 24, 2012
Reporter: wushi, iDefense
Products: Firefox, Thunderbird, SeaMonkey

Fixed in: Firefox 12.0
  Firefox ESR 10.0.4
  Thunderbird 12.0
  Thunderbird ESR 10.0.4
  SeaMonkey 2.9

Description

Security research firm iDefense reported that researcher wushi of team509 discovered a memory corruption on Windows Vista and Windows 7 systems with hardware acceleration disabled or using incompatible video drivers. This is created by using cairo-dwrite to attempt to render fonts on an unsupported code path. This corruption causes a potentially exploitable crash on affected systems.

References