Back to search
CVE-2024-11705
Published: Nov 26, 2024
Modified: Nov 27, 2024
PUBLISHED
Description
`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred, leading to crashes. This behavior conflicted with the PKCS#11 v3.0 specification, which allows `phKey` to be NULL for certain mechanisms. This vulnerability affects Firefox < 133 and Thunderbird < 133.
| Vendor | Product | Versions |
|---|---|---|
Mozilla | Firefox | affected unspecified - < 133 |
Mozilla | Thunderbird | affected unspecified - < 133 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now