The vulnerability is caused by an integer overflow error in the Color Management Module (CMM) when processing a malformed "pseq" tag within an ICC profile, which could be exploited by attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.
Disclosure Timeline:
2010-12-21 - Vulnerability Discovered
2011-06-09 - Public disclosure