A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox < 133, Thunderbird < 133, Firefox ESR < 128.7, and Thunderbird < 128.7.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade firefox-esrUpgrade thunderbird | Feb 7, 2025 | Nov 26, 2024 |
| Freebsd | — | Upgrade firefox-esrUpgrade thunderbirdUpgrade firefox | Apr 15, 2025 | Apr 13, 2025 |
| Gentoo Linux | — | Upgrade dev-lang/spidermonkey.Upgrade www-client/firefox.Upgrade mail-client/thunderbird.Upgrade mail-client/thunderbird-bin.Upgrade www-client/firefox-bin. | Jan 24, 2025 | Nov 26, 2024 |
| Mfsa2024 63 | — | Upgrade to Mozilla Firefox version 133.0 | Nov 27, 2024 | Nov 26, 2024 |
| Mfsa2025 09 | — | Upgrade to Mozilla Firefox ESR version 128.7 | Feb 5, 2025 | Nov 26, 2024 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 128.7 | Nov 27, 2024 | Nov 26, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 26, 2024 |
| Suse | — | Upgrade MozillaThunderbird-translations-otherUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations-otherUpgrade mozjs128-develUpgrade libmozjs-128-0Upgrade MozillaFirefox-translations-commonUpgrade mozillafirefox-branding-upstreamUpgrade MozillaThunderbird-translations-commonUpgrade mozjs128Upgrade MozillaThunderbirdUpgrade MozillaFirefox-devel | Dec 5, 2025 | Feb 5, 2025 |
| Ubuntu | — | Upgrade firefox | Dec 4, 2024 | Nov 26, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub