You are here: Security Center > Mozilla Foundation Security Advisories > MFSA 2011-04

Mozilla Foundation Security Advisory 2011-04

Title: Buffer overflow in JavaScript upvarMap
Impact: Critical
Announced: March 1, 2011
Reporter: Christian Holler
Products: Firefox, SeaMonkey

Fixed in: Firefox 3.6.14
  Firefox 3.5.17
  SeaMonkey 2.0.12


Security researcher Christian Holler reported that the JavaScript engine's internal memory mapping of non-local JS variables contained a buffer overflow which could potentially be used by an attacker to run arbitrary code on a victim's computer.