CVE-2024-11704 — Double Free in Mozilla Firefox
Severity
9.8CRITICALNVD
OSV4.3
EPSS
0.2%
top 57.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 26
Latest updateDec 3
Description
A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox < 133, Thunderbird < 133, Firefox ESR < 128.7, and Thunderbird < 128.7.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages7 packages
🔴Vulnerability Details
4CVEList▶
CVE-2024-11704: A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path↗2024-11-26
GHSA▶
GHSA-h8gv-f7pf-7c4p: A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path↗2024-11-26
OSV▶
CVE-2024-11704: A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path↗2024-11-26
📋Vendor Advisories
7Red Hat
▶
Debian▶
CVE-2024-11704: firefox - A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` w...↗2024