First published: Tue Apr 21 2020(Updated: )
A flaw was found in NSS, where it is vulnerable to RSA key generation cache timing side-channel attacks. An attacker with sufficient access to mount cache timing attacks during the RSA key generation process could recover the private key. The highest threat to this flaw is to confidentiality.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/nspr | <0:4.25.0-2.el7_9 | 0:4.25.0-2.el7_9 |
redhat/nss | <0:3.53.1-3.el7_9 | 0:3.53.1-3.el7_9 |
redhat/nss-softokn | <0:3.53.1-6.el7_9 | 0:3.53.1-6.el7_9 |
redhat/nss-util | <0:3.53.1-1.el7_9 | 0:3.53.1-1.el7_9 |
redhat/nspr | <0:4.25.0-2.el8_2 | 0:4.25.0-2.el8_2 |
redhat/nss | <0:3.53.1-11.el8_2 | 0:3.53.1-11.el8_2 |
Mozilla Thunderbird | <78 | 78 |
redhat/nss | <3.53.1 | 3.53.1 |
Mozilla Firefox | <78 | 78 |
Mozilla Firefox | <78.0 | |
Fedoraproject Fedora | =32 | |
openSUSE Leap | =15.1 | |
openSUSE Leap | =15.2 | |
Debian Debian Linux | =9.0 | |
debian/nss | 2:3.61-1+deb11u3 2:3.87.1-1 2:3.103-1 |
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The vulnerability ID for this flaw is CVE-2020-12402.
The severity of CVE-2020-12402 is medium, with a severity value of 4.4.
Mozilla Firefox version up to 78, Red Hat NSS version up to 3.53.1, Red Hat NSPR version up to 4.25.0-2.el7_9, Ubuntu NSS version up to 2:3.53.1, Ubuntu NSS version up to 3.28.4-0ubuntu0.14.04.5+.
Update Mozilla Firefox to version 78, update Red Hat NSS to version 3.53.1, update Red Hat NSPR to version 4.25.0-2.el7_9, update Ubuntu NSS to version 2:3.53.1, update Ubuntu NSS to version 3.28.4-0ubuntu0.14.04.5+.
Yes, the references for CVE-2020-12402 are: - [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1631597) - [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2020-24/) - [Mozilla NSS Repository](https://hg.mozilla.org/projects/nss/rev/699541a7793bbe9b20f1d73dc49e25c6054aa4c1)