The vulnerability is caused by an integer overflow error in the Color Management Module (CMM) when processing a malformed "mluc" tag within an ICC profile, which could be exploited by attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.
Disclosure Timeline:
2011-01-07 - Vulnerability Discovered
2011-06-09 - Public disclosure