PT-2019-5154 · Mozilla+5 · Firefox Esr+7

Craig Disselkoen

·

Published

2019-09-27

·

Updated

2024-06-15

·

CVE-2019-11745

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 71 Firefox ESR versions prior to 68.3 Thunderbird versions prior to 68.3
Description The issue is related to a buffer out of bounds write in memory when using a block cipher for encryption. If a call to NSC EncryptUpdate was made with data smaller than the block size, it could result in a small out of bounds write, potentially causing heap corruption and a crash. This could allow a remote attacker to gain unauthorized access to information and compromise its integrity and availability.
Recommendations For Firefox versions prior to 71, update to version 71 or later. For Firefox ESR versions prior to 68.3, update to version 68.3 or later. For Thunderbird versions prior to 68.3, update to version 68.3 or later.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3212
ALT-PU-2019-3237
ALT-PU-2019-3239
ALT-PU-2019-3264
ALT-PU-2020-1166
ALT-PU-2020-1515
ALT-PU-2020-1616
ALT-PU-2020-1617
ALT-PU-2020-2408
ALT-PU-2020-2933
ALT-PU-2021-1368
BDU:2020-01824
CESA-2019_4114
CESA-2019_4152
CESA-2019_4190
CVE-2019-11745
DLA-2008-1
DLA-2388-1
DSA-4579-1
MGASA-2019-0374
OPENSUSE-SU-2020:0002-1
OPENSUSE-SU-2020:0003-1
OPENSUSE-SU-2020:0008-1
OPENSUSE-SU-2020_0002-1
OPENSUSE-SU-2020_0008-1
OPENSUSE-SU-2024:11058-1
RHSA-2019:4114
RHSA-2019:4152
RHSA-2019:4190
RHSA-2019_4114
RHSA-2019_4152
RHSA-2019_4190
RHSA-2020:0243
RHSA-2020:0466
RHSA-2020:1267
RHSA-2020:1345
RHSA-2020:1461
SUSE-SU-2019:14260-1
SUSE-SU-2019:3337-1
SUSE-SU-2019:3339-1
SUSE-SU-2019:3347-1
SUSE-SU-2019:3395-1
SUSE-SU-2019_14260-1
SUSE-SU-2019_3337-1
SUSE-SU-2019_3347-1
SUSE-SU-2020:0088-1
SUSE-SU-2020:14418-1
SUSE-SU-2020_0088-1
USN-4203-1
USN-4203-2
USN-4216-1
USN-4216-2
USN-4241-1
USN-4335-1

Affected Products

Alt Linux
Centos
Firefox
Firefox Esr
Red Hat
Suse
Thunderbird
Ubuntu