Do your applications use this vulnerable package?
Test your applications
Overview
When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
References
- ADVISORY
- CONFIRM
- Debian Security Tracker
- GENTOO
- GENTOO
- GENTOO
- MISC
- MLIST
- Mozilla Security Advisory
- Mozilla Security Advisory
- Mozilla Security Advisory
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- REDHAT
- REDHAT
- RedHat Bugzilla Bug
- UBUNTU
- Ubuntu CVE Tracker
- Ubuntu Security Advisory
CVSS Score
8.8
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2019-11745
- CWE
- CWE-787
- Snyk ID
- SNYK-DEBIAN9-NSS-535471
- Disclosed
- 08 Jan, 2020
- Published
- 24 Nov, 2019