CVE-2024-11704Double Free in Mozilla Firefox

CWE-415Double Free12 documents8 sources
Severity
9.8CRITICALNVD
OSV4.3
EPSS
0.2%
top 57.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 26
Latest updateDec 3

Description

A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox < 133, Thunderbird < 133, Firefox ESR < 128.7, and Thunderbird < 128.7.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages7 packages

CVEListV5mozilla/thunderbirdunspecified133+1
NVDmozilla/thunderbird129.0133.0+1
Debianmozilla/thunderbird< 1:128.7.0esr-1~deb11u1+3
CVEListV5mozilla/firefoxunspecified133
NVDmozilla/firefox< 128.7.0+1

🔴Vulnerability Details

4
OSV
firefox vulnerabilities2024-12-03
CVEList
CVE-2024-11704: A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path2024-11-26
GHSA
GHSA-h8gv-f7pf-7c4p: A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path2024-11-26
OSV
CVE-2024-11704: A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path2024-11-26

📋Vendor Advisories

7
Ubuntu
Firefox vulnerabilities2024-12-03
Red Hat
firefox: thunderbird: Potential Double-Free Vulnerability in PKCS#7 Decryption Handling2024-11-26
Debian
CVE-2024-11704: firefox - A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` w...2024
Mozilla
Mozilla Foundation Security Advisory 2024-63: CVE-2024-11704
Mozilla
Mozilla Foundation Security Advisory 2025-09: CVE-2024-11704
CVE-2024-11704 — Double Free in Mozilla Firefox | cvebase