CVE-2019-11745
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
Affected (17)
Products: Mozilla: Firefox, Firefox Esr, Thunderbird · Opensuse: Leap · Canonical: Ubuntu Linux · +3 more
Show all products
Mozilla: Firefox, Firefox Esr, Thunderbird · Opensuse: Leap · Canonical: Ubuntu Linux · Debian: Debian Linux · Redhat: Enterprise Linux Server Aus · Siemens: Ruggedcom Rox Mx5000 Firmware, Ruggedcom Rox Rx1400 Firmware, Ruggedcom Rox Rx1500 Firmware, Ruggedcom Rox Rx1501 Firmware, Ruggedcom Rox Rx1510 Firmware, Ruggedcom Rox Rx1511 Firmware, Ruggedcom Rox Rx1512 Firmware, Ruggedcom Rox Rx5000 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 71.0 | |
| Before 68.3 | |
| Before 68.3.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 16.04 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.6 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.14.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Rox Mx5000 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.14.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Rox Rx1400 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.14.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Rox Rx1500 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.14.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Rox Rx1501 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.14.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Rox Rx1510 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.14.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Rox Rx1511 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.14.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Rox Rx1512 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.14.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Rox Rx5000 | All versions |
References (34)
Source: security@mozilla.org
Mailing ListThird Party Advisory
Source: security@mozilla.org
Issue TrackingMailing ListThird Party Advisory
Source: security@mozilla.org
Mailing ListThird Party Advisory
Source: security@mozilla.org
Issue TrackingPatchVendor Advisory
Source: security@mozilla.org
Third Party Advisory
Source: security@mozilla.org
Mailing ListThird Party Advisory
Source: security@mozilla.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.