A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox < 133, Thunderbird < 133, Firefox ESR < 128.7, and Thunderbird < 128.7.
2024-11-26T14:15:19.910
2025-04-07T19:40:06.320
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mozilla | firefox | < 128.7.0 | Yes |
Application | mozilla | firefox | < 133.0 | Yes |
Application | mozilla | thunderbird | < 128.7.0 | Yes |
Application | mozilla | thunderbird | < 133.0 | Yes |