VDB

DEBIAN-CVE-2024-11696

DEBIAN-CVE-2024-11696 PUBLISHED CVSS 5.400000095367432 MEDIUM

The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest, could have caused runtime errors that disrupted the signature validation process. As a result, the enforcement of signature validation for unrelated add-ons may have been bypassed. Signature validation in this context is used to ensure that third-party applications on the user's computer have not tampered with the user's extensions, limiting the impact of this issue. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.

Risk Scores

CVSS v3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersions
Debian:14thunderbird0, 0, 0
Debian:11firefox-esr115.0.2, 91.9.1, 91.9.0
Debian:12thunderbird1:102.12.0-1, 1:102.12.0-1~deb11u1, 1:102.13.0-1
Debian:13thunderbird0, 0, 0
Debian:12firefox-esr*, 0, 102.12.0esr-1
Debian:13firefox-esr0, 0, 0
Debian:11thunderbird91.5.0-2, 91.5.0-2, 91.5.0-1
Debian:14firefox-esr0, 0, 0

Timeline

  • Nov 26, 2024 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›