In Firefox before 68.0, when importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library.
In Firefox before 68.0, when importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library.
https://www.mozilla.org/en-US/security/advisories/mfsa2019-21/#CVE-2019-11719 https://bugzilla.mozilla.org/show_bug.cgi?id=1540541