Related Vulnerabilities: CVE-2019-11729  

Empty or malformed p256-ECDH public keys may trigger a segmentation fault in Firefox before 68.0 due values being improperly sanitized before being copied into memory and used.

Severity Medium

Remote Yes

Type Denial of service

Description

Empty or malformed p256-ECDH public keys may trigger a segmentation fault in Firefox before 68.0 due values being improperly sanitized before being copied into memory and used.

AVG-1002 firefox 67.0.4-2 68.0-1 Critical Testing

https://www.mozilla.org/en-US/security/advisories/mfsa2019-21/#CVE-2019-11729
https://bugzilla.mozilla.org/show_bug.cgi?id=1515342