Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-38vr-4p57-8h9g

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

EPSS

Процентиль: 22%
0.00072
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-200
CWE-203

Связанные уязвимости

CVSS3: 4.7
ubuntu
около 5 лет назад

When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS3: 4.4
redhat
больше 5 лет назад

When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS3: 4.7
nvd
около 5 лет назад

When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS3: 4.7
debian
около 5 лет назад

When converting coordinates from projective to affine, the modular inv ...

CVSS3: 5.5
fstec
больше 5 лет назад

Уязвимость функции модульной инверсии набора библиотек NSS (Network Security Services), позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 22%
0.00072
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-200
CWE-203