Mozilla Firefox 10.x < 10.0.2 'png_decompress_chunk' Integer Overflow
PVS ID: 6325 FAMILY: Web Clients RISK: HIGH NESSUS ID:58005
Description: Synopsis :\n\nThe remote host has a web browser installed that is affected by an integer overflow vulnerability.\n\nFor your information, the observed version of Firefox is : \n %L \n\nVersions of Firefox 10.x earlier than 10.0.2 are potentially affected by an integer overflow vulnerability. An integer overflow error exists in 'libpng', a library used by this application. When decompressing certain PNG image files, this error can allow a heap-based buffer overflow which can crash the application or potentially allow code execution.

Solution: Upgrade to Firefox 10.0.2 or later.

CVE-2011-3026


Copyright Tenable Network Security Inc. 2012