U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-11696

Change History

New CVE Received from Mozilla Corporation 11/26/2024 9:15:19 AM

Action Type Old Value New Value
Added Description

								
							
							
						
The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest, could have caused runtime errors that disrupted the signature validation process. As a result, the enforcement of signature validation for unrelated add-ons may have been bypassed.  Signature validation in this context is used to ensure that third-party applications on the user's computer have not tampered with the user's extensions, limiting the impact of this issue. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
Added Reference

								
							
							
						
https://bugzilla.mozilla.org/show_bug.cgi?id=1929600
Added Reference

								
							
							
						
https://www.mozilla.org/security/advisories/mfsa2024-63/
Added Reference

								
							
							
						
https://www.mozilla.org/security/advisories/mfsa2024-64/
Added Reference

								
							
							
						
https://www.mozilla.org/security/advisories/mfsa2024-67/
Added Reference

								
							
							
						
https://www.mozilla.org/security/advisories/mfsa2024-68/