CVE-2019-11729: Buffer Overflow
Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used.
Other sources
Mozilla Firefox is vulnerable to a denial of service, caused by the improperly validation of empty or malformed p256-ECDH public keys before being copied into memory and used. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause the browser to crash.
— IBM
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-11729?
CVE-2019-11729 is a vulnerability in Mozilla Firefox that can be exploited to cause a denial of service.
How does CVE-2019-11729 work?
The vulnerability occurs when empty or malformed p256-ECDH public keys are not properly validated and copied into memory, leading to a segmentation fault.
What is the severity of CVE-2019-11729?
CVE-2019-11729 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2019-11729?
Mozilla Firefox versions up to and including 68.0, Mozilla Firefox ESR versions up to and including 60.8.0, and Mozilla Thunderbird versions up to and including 60.8.0 are affected.
How can I fix CVE-2019-11729?
Update your Mozilla Firefox, Mozilla Firefox ESR, and Mozilla Thunderbird to versions 68.0.1, 60.8.1, and 68.0.1 respectively.