FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Mozilla -- null pointer dereference

Affected packages
firefox < 133.0,2
thunderbird < 133.0

Details

VuXML ID ba6361be-1887-11f0-a8ce-b42e991fc52e
Discovery 2024-11-26
Entry 2025-04-13

security@mozilla.org reports:

A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed or improperly formatted input files.

References

CVE Name CVE-2024-11706
URL https://nvd.nist.gov/vuln/detail/CVE-2024-11706