USN-4417-1: NSS vulnerability
Published Jul 6, 2020
·Updated
Cesar Pereida, Billy Bob Brumley, Yuval Yarom, and Nicola Tuveri discovered that NSS incorrectly handled RSA key generation. A local attacker could possibly use this issue to perform a timing attack and recover RSA keys.
Affected Software
8 affected componentsFixes available
All of the following
ubuntu/libnss3<2:3.49.1-1ubuntu1.2
2:3.49.1-1ubuntu1.2
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libnss3<2:3.45-1ubuntu2.4
2:3.45-1ubuntu2.4
Ubuntu Ubuntu=19.10
All of the following
ubuntu/libnss3<2:3.35-2ubuntu2.9
2:3.35-2ubuntu2.9
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libnss3<2:3.28.4-0ubuntu0.16.04.12
2:3.28.4-0ubuntu0.16.04.12
Ubuntu Ubuntu=16.04
Event History
Jul 6, 2020
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is USN-4417-1.
2
What is the name of this vulnerability?
The name of this vulnerability is NSS vulnerability.
3
Who discovered this vulnerability?
Cesar Pereida, Billy Bob Brumley, Yuval Yarom, and Nicola Tuveri discovered this vulnerability.
4
What is the impact of this vulnerability?
A local attacker could use this vulnerability to perform a timing attack and recover RSA keys.
5
How can I fix this vulnerability?
To fix this vulnerability, update the libnss3 package to version 2:3.49.1-1ubuntu1.2 (for Ubuntu 20.04) or the respective version for your Ubuntu version.