CVE-2024-11696Improper Verification of Cryptographic Signature in Mozilla Firefox

Severity
5.4MEDIUMNVD
OSV4.3
EPSS
0.0%
top 86.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 26
Latest updateDec 3

Description

The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest, could have caused runtime errors that disrupted the signature validation process. As a result, the enforcement of signature validation for unrelated add-ons may have been bypassed. Signature validation in this context is used to ensure that third-party applications on the user's computer have not t

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages7 packages

CVEListV5mozilla/firefoxunspecified133
NVDmozilla/firefox< 128.5.0+1
CVEListV5mozilla/firefox_esrunspecified128.5
CVEListV5mozilla/thunderbirdunspecified133+1
NVDmozilla/thunderbird129.0133.0+1

🔴Vulnerability Details

4
OSV
firefox vulnerabilities2024-12-03
CVEList
CVE-2024-11696: The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification2024-11-26
GHSA
GHSA-g5wv-cvf4-2r98: The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification2024-11-26
OSV
CVE-2024-11696: The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification2024-11-26

📋Vendor Advisories

7
Ubuntu
Firefox vulnerabilities2024-12-03
Red Hat
firefox: thunderbird: Unhandled Exception in Add-on Signature Verification2024-11-26
Debian
CVE-2024-11696: firefox - The application failed to account for exceptions thrown by the `loadManifestFrom...2024
Mozilla
Mozilla Foundation Security Advisory 2024-67: CVE-2024-11696
Mozilla
Mozilla Foundation Security Advisory 2024-68: CVE-2024-11696
CVE-2024-11696 — Mozilla Firefox vulnerability | cvebase