A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox < 133 and Thunderbird < 133.
History

Tue, 26 Nov 2024 13:45:00 +0000

Type Values Removed Values Added
Description A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox < 133 and Thunderbird < 133.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2024-11-26T13:33:59.991Z

Updated: 2024-11-26T13:33:59.991Z

Reserved: 2024-11-25T16:29:45.930Z

Link: CVE-2024-11704

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2024-11-26T14:15:19.910

Modified: 2024-11-26T14:15:19.910

Link: CVE-2024-11704

cve-icon Redhat

No data.