The vulnerability is caused by an integer overflow error in the Color Management Module (CMM) when processing a malformed "scrn" tag within an ICC profile, which could be exploited by attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.
Disclosure Timeline:
2010-12-14 - Vulnerability Discovered
2011-06-09 - Public disclosure