Back

MEDIUM

firefox: thunderbird: Null Pointer Dereference in PKCS#12 Utility

Published Nov 26, 2024

Description

A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed or improperly formatted input files. This vulnerability affects Firefox < 133 and Thunderbird < 133.

Affected products

Remediation

Red Hat statement

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Nov 26, 2024
Updated Nov 26, 2024
Reserved Nov 25, 2024
CISA Vulnrichment
Updated Nov 26, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Nov 26, 2024
ENISA EUVD
Assigner mozilla
Published Nov 26, 2024
Updated Nov 26, 2024
Exploited since n/a
EUVD-2024-33970