UBUNTU-CVE-2019-11745
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-11745
UBUNTU-CVE-2019-11745
Summary:
Details: When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
References: https://ubuntu.com/security/CVE-2019-11745, https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.44.3_release_notes, https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.47.1_release_notes, https://www.mozilla.org/en-US/security/advisories/mfsa2019-38/#CVE-2019-11745, https://ubuntu.com/security/notices/USN-4203-1, https://ubuntu.com/security/notices/USN-4203-2, https://ubuntu.com/security/notices/USN-4216-1, https://ubuntu.com/security/notices/USN-4216-2, https://ubuntu.com/security/notices/USN-4241-1, https://ubuntu.com/security/notices/USN-4335-1, https://www.cve.org/CVERecord?id=CVE-2019-11745
Affected packages
Package
Name: nss
Purl: pkg:deb/ubuntu/nss@2:3.28.4-0ubuntu0.14.04.5+esm2?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
