firefox: thunderbird: Null Pointer Dereference in PKCS#12 Utility
Published Nov 26, 2024
6.5
MEDIUMCVSS 3.1
EPSS 0.47%
Description
A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed or improperly formatted input files. This vulnerability affects Firefox < 133 and Thunderbird < 133.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<133
- Version
-
- Version unspecifiedStatusaffectedConstraints<133
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mozilla | Firefox | n/a |
| ||||||
| Mozilla | Thunderbird | n/a |
|
- < 133.0
- < 133.0
No data.
Red Hat Enterprise Linux 10
firefox
Under investigation
Red Hat Enterprise Linux 10
thunderbird
Under investigation
Red Hat Enterprise Linux 6
firefox
Out of support scope
Red Hat Enterprise Linux 6
thunderbird
Out of support scope
Red Hat Enterprise Linux 7
firefox
Out of support scope
Red Hat Enterprise Linux 7
thunderbird
Out of support scope
Red Hat Enterprise Linux 8
firefox
Fix deferred
Red Hat Enterprise Linux 8
thunderbird
Fix deferred
Red Hat Enterprise Linux 9
firefox
Under investigation
Red Hat Enterprise Linux 9
firefox:flatpak/firefox
Under investigation
Red Hat Enterprise Linux 9
thunderbird
Under investigation
Red Hat Enterprise Linux 9
thunderbird:flatpak/thunderbird
Under investigation
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | firefox | Under investigation | n/a |
| Red Hat Enterprise Linux 10 | thunderbird | Under investigation | n/a |
| Red Hat Enterprise Linux 6 | firefox | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | thunderbird | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | firefox | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | thunderbird | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | firefox | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | thunderbird | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | firefox | Under investigation | n/a |
| Red Hat Enterprise Linux 9 | firefox:flatpak/firefox | Under investigation | n/a |
| Red Hat Enterprise Linux 9 | thunderbird | Under investigation | n/a |
| Red Hat Enterprise Linux 9 | thunderbird:flatpak/thunderbird | Under investigation | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
References (8)
- https://access.redhat.com/security/cve/CVE-2024-11706 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1923767 Issue TrackingPermissions Required
- https://bugzilla.redhat.com/show_bug.cgi?id=2328951 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-33970 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-11706
- https://www.cve.org/CVERecord?id=CVE-2024-11706
- https://www.mozilla.org/security/advisories/mfsa2024-63/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-67/ Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-11706 | Vendor Advisory | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1923767 | Issue TrackingPermissions Required | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2328951 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-33970 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-11706 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-11706 | ||
| https://www.mozilla.org/security/advisories/mfsa2024-63/ | Vendor Advisory | |
| https://www.mozilla.org/security/advisories/mfsa2024-67/ | Vendor Advisory |
Change history (0)
No recorded changes yet.