Do your applications use this vulnerable package?
Test your applications
Overview
Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
References
CVSS Score
7.5
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2019-11729
- CWE
- CWE-119
- Snyk ID
- SNYK-DEBIAN9-NSS-453526
- Disclosed
- 23 Jul, 2019
- Published
- 24 Jul, 2019