CVE-2019-11745: Canonical Ubuntu Linux

High severity, CVSS 8.8. EPSS: 3% chance of exploitation in the next 30 days.

When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.10 only
  • Debian Debian Linux: version 9.0 only
  • Mozilla Firefox: before 71.0 (fixed in 71.0)
  • Mozilla Firefox ESR: before 68.3 (fixed in 68.3)
  • Mozilla Thunderbird: before 68.3.0 (fixed in 68.3.0)
  • Opensuse Leap: version 15.1 only
  • Red Hat Enterprise Linux Server Aus: version 6.6 only
  • Siemens Ruggedcom Rox MX5000 Firmware: before 2.14.0 (fixed in 2.14.0)
  • Siemens Ruggedcom Rox RX1400 Firmware: before 2.14.0 (fixed in 2.14.0)
  • Siemens Ruggedcom Rox RX1500 Firmware: before 2.14.0 (fixed in 2.14.0)
  • Siemens Ruggedcom Rox RX1501 Firmware: before 2.14.0 (fixed in 2.14.0)
  • Siemens Ruggedcom Rox RX1510 Firmware: before 2.14.0 (fixed in 2.14.0)
  • Siemens Ruggedcom Rox RX1511 Firmware: before 2.14.0 (fixed in 2.14.0)
  • Siemens Ruggedcom Rox RX1512 Firmware: before 2.14.0 (fixed in 2.14.0)
  • Siemens Ruggedcom Rox RX5000 Firmware: before 2.14.0 (fixed in 2.14.0)

Published 2020-01-08. Last modified 2026-06-17.