ZeroHour

CVE-2019-11745

CVSS 3.1
8.8 high
EPSS
3%p87
Published
()
Modified
Description

When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

Vendors
mozillaopensusecanonicaldebianredhatsiemens
Products
firefox, firefox esr, thunderbird, leap, ubuntu linux, debian linux, enterprise linux server aus, ruggedcom rox mx5000 firmware, ruggedcom rox rx1400 firmware, ruggedcom rox rx1500 firmware, ruggedcom rox rx1501 firmware, ruggedcom rox rx1510 firmware
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.