CVE Database
/

CVE-2024-11705

Back to search

CVE-2024-11705

Published: Nov 26, 2024

Modified: Nov 27, 2024

PUBLISHED

Description

`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred, leading to crashes. This behavior conflicted with the PKCS#11 v3.0 specification, which allows `phKey` to be NULL for certain mechanisms. This vulnerability affects Firefox < 133 and Thunderbird < 133.

VendorProductVersions

Mozilla

Firefox

affected
unspecified - < 133

Mozilla

Thunderbird

affected
unspecified - < 133

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now