CVE-2024-11704 Information

Description

A double-free issue could have occurred in sec_pkcs7_decoder_start_decrypt() when handling an error path. Under specific conditions the same symmetric key could have been freed twice potentially leading to memory corruption. This vulnerability affects Firefox < 133 and Thunderbird < 133.

Reference

https://bugzilla.mozilla.org/show_bug.cgi?id=1899402 https://www.mozilla.org/security/advisories/mfsa2024-63/ https://www.mozilla.org/security/advisories/mfsa2024-67/

Share on: