I'm trying to use mrc-converter-suite to convert my Firefox (87) passwords on Ubuntu Linux, I know its not Windows or MacOS but perhaps someone can still give me some pointers on what to look at after all its still perl.
It is possible for a UTF8 string with invalid sequences to trigger a heap overflow of converted Unicode data. Exploitability would depend on the attackers ability to get the stringinto the buggy converter. General web content is converted elsewhere but we can't rule out the possibility of a successful attack.