Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fq62-4j88-qq7x

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.

NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.

EPSS

Процентиль: 28%
0.00101
Низкий

Дефекты

CWE-203

Связанные уязвимости

CVSS3: 4.4
ubuntu
больше 5 лет назад

NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.

CVSS3: 4.4
redhat
больше 5 лет назад

NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.

CVSS3: 4.4
nvd
больше 5 лет назад

NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.

CVSS3: 4.4
debian
больше 5 лет назад

NSS has shown timing differences when performing DSA signatures, which ...

CVSS3: 3.7
fstec
больше 5 лет назад

Уязвимость подписи DSA веб-браузеров программного обеспечения Firefox, Firefox-esr и Thunderbird, связанная с раскрытием информации в результате расхождений, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 28%
0.00101
Низкий

Дефекты

CWE-203