ASA-2019-00440 – Mozilla Firefox: Out-of-bounds read when importing curve25519 private key


Allele Security Alert

ASA-2019-00440

Identifier(s)

ASA-2019-00440, CVE-2019-11719, MFSA2019-21

Title

Out-of-bounds read when importing curve25519 private key

Vendor(s)

Mozilla

Product(s)

Mozilla Firefox

Affected version(s)

Mozilla Firefox version before 68

Fixed version(s)

Mozilla Firefox version 68

Proof of concept

Unknown

Description

When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to information disclosure.

Technical details

Unknown

Credits

Henry Corrigan-Gibbs

Reference(s)

Mozilla Foundation Security Advisory 2019-21
https://www.mozilla.org/en-US/security/advisories/mfsa2019-21/#CVE-2019-11719

Bug 1540541
https://bugzilla.mozilla.org/show_bug.cgi?id=1540541

CVE-2019-11719
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11719

CVE-2019-11719
https://nvd.nist.gov/vuln/detail/CVE-2019-11719

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: July 17, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.