The lut_inverse_interp16 function in the QCMS library in Mozilla Firefox before 41.0 allows remote attackers to obtain sensitive information or cause a denial of service (buffer over-read and application crash) via crafted attributes in the ICC 4 profile of an image.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | - | 40.0.3.x |