First published: Tue Dec 12 2023(Updated: )
Timing side-channel in PKCS#1 v1.5 decryption depadding code
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Network Security Services (NSS) | <3.61 | 3.61 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
MFSA2023-53 has been classified with a critical severity level.
To fix MFSA2023-53, update your Mozilla Network Security Services (NSS) to version 3.61 or later.
MFSA2023-53 addresses a timing side-channel vulnerability in the PKCS#1 v1.5 decryption depadding code.
MFSA2023-53 affects all versions of Mozilla Network Security Services (NSS) prior to 3.61.
A timing side-channel vulnerability allows an attacker to gain sensitive information based on the time taken to execute cryptographic operations.