CVE-2019-11719

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
23/07/2019
Last modified:
25/11/2025

Description

When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to information disclosure. This vulnerability affects Firefox ESR

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 60.8.0 (excluding)
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 68.0 (excluding)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* 60.8.0 (excluding)


References to Advisories, Solutions, and Tools