The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to execute arbitrary code via certain optional Certificate Authority name arguments, which causes an invalid array index and triggers a buffer overflow.
Get an AI-powered plain-language explanation of this vulnerability and remediation steps.
Login to generate AI explanation110 reference(s) from NVD