When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
71.0+build5-0ubuntu0.16.04.12:3.28.4-0ubuntu0.16.04.81:68.7.0+build1-0ubuntu0.16.04.271.0+build5-0ubuntu0.18.04.12:3.35-2ubuntu2.51:68.4.1+build1-0ubuntu0.18.04.12:3.28.4-0ubuntu0.14.04.5+esm2Exploitability
AV:NAC:LPR:NUI:RScope
S:UImpact
C:HI:HA:HCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H