PT-2024-8826 · Mozilla+9 · Firefox+10

Rob Wu

·

Published

2024-11-25

·

Updated

2026-05-19

·

CVE-2024-11696

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Firefox versions prior to 133 Firefox ESR versions prior to 128.5 Thunderbird versions prior to 133 Thunderbird versions prior to 128.5
Description: The application failed to account for exceptions thrown by the loadManifestFromFile method during add-on signature verification. This flaw could have caused runtime errors that disrupted the signature validation process, potentially bypassing the enforcement of signature validation for unrelated add-ons. Signature validation is used to ensure that third-party applications have not tampered with the user's extensions.
Recommendations: For Firefox versions prior to 133, update to version 133 or later to resolve the issue. For Firefox ESR versions prior to 128.5, update to version 128.5 or later to resolve the issue. For Thunderbird versions prior to 133, update to version 133 or later to resolve the issue. For Thunderbird versions prior to 128.5, update to version 128.5 or later to resolve the issue. As a temporary workaround, consider disabling the loadManifestFromFile method until a patch is available.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:10591
ALSA-2024:10592
ALSA-2024:10702
ALSA-2024:10752
ALSA-2026:18479
ALT-PU-2024-16375
ALT-PU-2024-16377
ALT-PU-2024-16378
ALT-PU-2025-1049
ALT-PU-2025-2027
ALT-PU-2025-2230
BDU:2024-10459
CESA-2024_10591
CESA-2024_10752
CVE-2024-11696
DLA-3969-1
DLA-3971-1
DSA-5820-1
DSA-5821-1
INFSA-2024_10591
INFSA-2024_10592
INFSA-2024_10702
INFSA-2024_10752
MGASA-2024-0383
MGASA-2024-0384
OESA-2024-2523
OESA-2025-1835
OPENSUSE-SU-2024:14533-1
OPENSUSE-SU-2024:14542-1
OPENSUSE-SU-2024:14572-1
OPENSUSE-SU-2024:14583-1
OPENSUSE-SU-2024_4086-1
OPENSUSE-SU-2024_4148-1
RHSA-2024:10591
RHSA-2024:10592
RHSA-2024:10667
RHSA-2024:10702
RHSA-2024:10703
RHSA-2024:10704
RHSA-2024:10710
RHSA-2024:10733
RHSA-2024:10734
RHSA-2024:10742
RHSA-2024:10743
RHSA-2024:10745
RHSA-2024:10748
RHSA-2024:10752
RHSA-2024:10844
RHSA-2024:10848
RHSA-2024:10849
RHSA-2024:10880
RHSA-2024:10881
RHSA-2024_10591
RHSA-2024_10592
RHSA-2024_10702
RHSA-2024_10752
RLSA-2024:10591
RLSA-2024:10752
SUSE-SU-2024:4074-1
SUSE-SU-2024:4086-1
SUSE-SU-2024:4148-1
USN-7134-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Linuxmint
Red Hat
Rocky Linux
Suse
Thunderbird
Ubuntu