First published: Mon Jul 27 2020(Updated: )
A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/nspr | <0:4.25.0-2.el7_9 | 0:4.25.0-2.el7_9 |
redhat/nss | <0:3.53.1-3.el7_9 | 0:3.53.1-3.el7_9 |
redhat/nss-softokn | <0:3.53.1-6.el7_9 | 0:3.53.1-6.el7_9 |
redhat/nss-util | <0:3.53.1-1.el7_9 | 0:3.53.1-1.el7_9 |
redhat/nss-softokn | <0:3.28.3-10.el7_4 | 0:3.28.3-10.el7_4 |
redhat/nss | <0:3.36.0-9.el7_6 | 0:3.36.0-9.el7_6 |
redhat/nss-softokn | <0:3.36.0-7.el7_6 | 0:3.36.0-7.el7_6 |
redhat/nss-softokn | <0:3.44.0-9.el7_7 | 0:3.44.0-9.el7_7 |
redhat/nss | <0:3.53.1-17.el8_3 | 0:3.53.1-17.el8_3 |
redhat/nss | <3.55 | 3.55 |
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 | |
Mozilla Network Security Services | <3.55 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2020-12403 is a vulnerability in Mozilla Network Security Services (NSS) that can allow a remote attacker to obtain sensitive information.
CVE-2020-12403 has a severity rating of 9.1 (Critical).
The affected software by CVE-2020-12403 includes Mozilla Firefox, IBM Cloud Pak for Security (CP4S), and Red Hat packages: nss, nspr, nss-softokn, and nss-util with specific versions.
A remote attacker can exploit CVE-2020-12403 by persuading a victim to visit a specially-crafted website.
You can find more information about CVE-2020-12403 at the following references: [Link 1](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1636771), [Link 2](https://access.redhat.com/security/cve/CVE-2020-12403), [Link 3](https://bugzilla.mozilla.org/show_bug.cgi?id=1636771).