Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cm2q-67xf-jw8c

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

EPSS

Процентиль: 22%
0.0007
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-203
CWE-327

Связанные уязвимости

CVSS3: 4.7
ubuntu
около 5 лет назад

During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS3: 4.4
redhat
больше 5 лет назад

During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS3: 4.7
nvd
около 5 лет назад

During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS3: 4.7
debian
около 5 лет назад

During ECDSA signature generation, padding applied in the nonce design ...

CVSS3: 4.4
fstec
больше 5 лет назад

Уязвимость набора библиотек NSS (Network Security Services), связанная с использованием криптографического алгоритма ECDSA (Elliptic Curve Digital Signature Algorithm), содержащего дефекты, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 22%
0.0007
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-203
CWE-327