CVE-2019-11729

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
23/07/2019
Last modified:
25/11/2025

Description

Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used. This vulnerability affects Firefox ESR

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 60.8.0 (excluding)
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 68.0 (excluding)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* 60.8.0 (excluding)


References to Advisories, Solutions, and Tools