Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-12401

Опубликовано: 08 окт. 2020
Источник: debian
EPSS Низкий

Описание

During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed80.0-1package
nssfixed2:3.55-1package

Примечания

  • https://hg.mozilla.org/projects/nss/rev/aeb2e583ee957a699d949009c7ba37af76515c20

  • https://bugzilla.mozilla.org/show_bug.cgi?id=1631573 (private)

  • https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.55_release_notes

  • https://www.mozilla.org/en-US/security/advisories/mfsa2020-36/#CVE-2020-12401

EPSS

Процентиль: 22%
0.0007
Низкий

Связанные уязвимости

CVSS3: 4.7
ubuntu
около 5 лет назад

During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS3: 4.4
redhat
больше 5 лет назад

During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS3: 4.7
nvd
около 5 лет назад

During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS3: 4.7
github
больше 3 лет назад

During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS3: 4.4
fstec
больше 5 лет назад

Уязвимость набора библиотек NSS (Network Security Services), связанная с использованием криптографического алгоритма ECDSA (Elliptic Curve Digital Signature Algorithm), содержащего дефекты, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 22%
0.0007
Низкий