Описание
Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
firefox | fixed | 121.0-1 | package | |
nss | fixed | 2:3.95-1 | package | |
nss | ignored | bookworm | package | |
nss | ignored | bullseye | package | |
nss | ignored | buster | package |
Примечания
https://www.mozilla.org/en-US/security/advisories/mfsa2023-56/#CVE-2023-6135
https://bugzilla.mozilla.org/show_bug.cgi?id=1853908 (not public)
Fixed via: https://bugzilla.mozilla.org/show_bug.cgi?id=1861728
https://hg.mozilla.org/projects/nss/rev/e68b42b773657000078d104aaccbe26e71a1e0be
Fixed via: https://bugzilla.mozilla.org/show_bug.cgi?id=1863605
https://hg.mozilla.org/projects/nss/rev/39f0db972e9d4803f386585bc4d8858ad6f019b8
nss issue relates to: https://bugzilla.mozilla.org/show_bug.cgi?id=1854438
nss issue relates to: https://bugzilla.mozilla.org/show_bug.cgi?id=1854439
EPSS
Связанные уязвимости
Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.
Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.
Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.
Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.
EPSS