CVE-2019-11745

Advisory lineage Upstream: 0 Downstream: 32
Modified
Published: 08 Jan 2020, 19:22
Last modified:04 Aug 2024, 23:03

Vulnerability Summary

Overall Risk (default)
medium
35/100
CVSS Score
8.8 HIGH
v3.1 (nvd)
EPSS Score
0.94% LOW
1% probability +0.13%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

08 Jan 2020, 19:22
Published
Vulnerability first disclosed
04 Aug 2024, 23:03
Last Modified
Vulnerability information updated

Description

When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

CVSS Metrics

  • v3.1HIGHScore: 8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 0.94% Percentile: 77%

Techniques & Countermeasures

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • canonicalubuntu_linux

    16.04 | 18.04 | 19.10

  • debiandebian_linux

    9.0

  • mozillafirefox

    < 71.0 | < 71

  • mozillafirefox_esr

    < 68.3

  • mozillathunderbird

    < 68.3.0 | < 68.3

  • opensuseleap

    15.1

  • redhatenterprise_linux_server_aus

    6.6

  • siemensruggedcom rox mx5000

    < 2.14.0

  • siemensruggedcom rox rx1400

    < 2.14.0

  • siemensruggedcom rox rx1500

    < 2.14.0

  • siemensruggedcom rox rx1501

    < 2.14.0

  • siemensruggedcom rox rx1510

    < 2.14.0

  • siemensruggedcom rox rx1511

    < 2.14.0

  • siemensruggedcom rox rx1512

    < 2.14.0

  • siemensruggedcom rox rx5000

    < 2.14.0

References (17)