Related Vulnerabilities: CVE-2019-11719  

In Firefox before 68.0, when importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library.

Severity Medium

Remote Yes

Type Information disclosure

Description

In Firefox before 68.0, when importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library.

AVG-1002 firefox 67.0.4-2 68.0-1 Critical Testing

https://www.mozilla.org/en-US/security/advisories/mfsa2019-21/#CVE-2019-11719
https://bugzilla.mozilla.org/show_bug.cgi?id=1540541