Endpoint Vulnerability

Out-of-bounds write with Updater and malicious MAR file

Description

Security researcher Holger Fuhrmannek reported that if the Updater opens a MAR format file with a specially crafted name, an out-of-bounds write will occur. This can lead to a potentially exploitable crash but requires that the malicious MAR format file be present on the local system and the Updater to be run to use it.

Affected Products

SeaMonkey

References

CVE-2015-4482,