MFSA2023-53: Timing side-channel in PKCS#1 v1.5 decryption depadding code
Published Dec 12, 2023
·Updated
Timing side-channel in PKCS#1 v1.5 decryption depadding code
Affected Software
1 affected componentFixes available
Mozilla nSS<3.61
3.61
Event History
Dec 12, 2023
Advisory Published
via Mozilla·12:00 AM
Frequently Asked Questions
1
What is the severity of MFSA2023-53?
MFSA2023-53 has been classified with a critical severity level.
2
How do I fix MFSA2023-53?
To fix MFSA2023-53, update your Mozilla Network Security Services (NSS) to version 3.61 or later.
3
What is the underlying issue in MFSA2023-53?
MFSA2023-53 addresses a timing side-channel vulnerability in the PKCS#1 v1.5 decryption depadding code.
4
Which versions of NSS are affected by MFSA2023-53?
MFSA2023-53 affects all versions of Mozilla Network Security Services (NSS) prior to 3.61.
5
What is a timing side-channel vulnerability as mentioned in MFSA2023-53?
A timing side-channel vulnerability allows an attacker to gain sensitive information based on the time taken to execute cryptographic operations.