First published: Tue Nov 26 2024(Updated: )
A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed or improperly formatted input files. This vulnerability affects Firefox < 133 and Thunderbird < 133.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/firefox | 135.0-1 | |
Thunderbird | <133 | 133 |
Firefox | <133 | 133 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-11706 is classified as a moderate severity vulnerability due to the potential for denial of service through a null pointer dereference.
To fix CVE-2024-11706, update Firefox or Thunderbird to version 133 or later.
CVE-2024-11706 affects Firefox versions less than 133 and Thunderbird versions less than 133.
CVE-2024-11706 is a null pointer dereference vulnerability that can occur when processing malformed or improperly formatted input files.
If CVE-2024-11706 is not addressed, it may result in application crashes or denial of service.