PT-2024-9372 · Mozilla+4 · Thunderbird+5

Marc Schoenefeld

·

Published

2024-11-26

·

Updated

2025-11-19

·

CVE-2024-11706

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Firefox versions prior to 133 Thunderbird versions prior to 133
Description: A null pointer dereference may have occurred in the pk12util tool, specifically in the SEC ASN1DecodeItem Util function, when handling malformed or improperly formatted input files. This issue can potentially allow a remote attacker to cause a denial of service.
Recommendations: For Firefox versions prior to 133, update to a version that includes the fix for this issue. For Thunderbird versions prior to 133, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting the use of the pk12util tool and the SEC ASN1DecodeItem Util function until a patch is available.

Fix

Improper Resource Release

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-16375
ALT-PU-2025-11100
ALT-PU-2025-14599
ALT-PU-2025-2230
ALT-PU-2025-5137
ALT-PU-2025-7695
BDU:2024-11062
CVE-2024-11706
OPENSUSE-SU-2024:14583-1
USN-7134-1

Affected Products

Alt Linux
Astra Linux
Firefox
Linuxmint
Thunderbird
Ubuntu