Firefox 3.6.2 fixes the following issues found in previous versions of Firefox 3.6:
- Fixed a critical security issue that could potentially allow remote code execution,the bus as follow:
WOFF heap corruption due to integer overflow
Proof of conceptEvgeny L. from Vulndisco reported a crash due to a buffer overflow in our WOFFparser. I am able to reproduce the crash, but the stack I get doesn't appearto be in font parser code. I'll try it in a debug build shortly to see if itlooks any different. Here's the crash report where it looks like we're callingnull:0bc35855-ee77-4c61-b469-c7c482100313To reproduce, run the attached python script ff1.py and loadhttp://localhost:8080/1.html
- Fixed several additional security issues.
- Fixed several stability issues.