CVE-2024-11704

Severity CVSS v4.0:
Pending analysis
Type:
CWE-415 Double Free
Publication date:
26/11/2024
Last modified:
03/11/2025

Description

A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* 128.7.0 (excluding)
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 133.0 (excluding)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* 128.7.0 (excluding)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* 129.0 (including) 133.0 (excluding)