Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-12401

Опубликовано: 30 июн. 2020
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

A flaw was found in nss. Using the EM side-channel, it is possible to extract the position of zero and non-zero wNAF digits while nss-certutil tool performs scalar multiplication during the ECDSA signature generation, leaking partial information about the ECDSA nonce. Given a small number of ECDSA signatures, this information can be used to steal the private key. The highest threat from this vulnerability is to data confidentiality.

Отчет

This is a side channel attack which can used to exact pirate keys when ECDSA signatures are being generated. This attack is only feasible when the attacker is local to the machine or in certain cross-VM scenarios where the signature is being generated. Attacks over the network or via the internet are not feasible.

Меры по смягчению последствий

This is a side channel attack which can used to exact pirate keys when ECDSA signatures are being generated. This attack is only feasible when the attacker is local to the machine or in certain cross-VM scenarios where the signature is being generated. Attacks over the network or via the internet are not feasible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5nssOut of support scope
Red Hat Enterprise Linux 6nssOut of support scope
Red Hat Enterprise Linux 7nsprFixedRHSA-2020:407629.09.2020
Red Hat Enterprise Linux 7nssFixedRHSA-2020:407629.09.2020
Red Hat Enterprise Linux 7nss-softoknFixedRHSA-2020:407629.09.2020
Red Hat Enterprise Linux 7nss-utilFixedRHSA-2020:407629.09.2020
Red Hat Enterprise Linux 8nssFixedRHSA-2021:053816.02.2021
Red Hat OpenShift Doopenshiftdo/odo-init-image-rhel7FixedRHSA-2021:094922.03.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-327
https://bugzilla.redhat.com/show_bug.cgi?id=1851294nss: ECDSA timing attack mitigation bypass

EPSS

Процентиль: 22%
0.0007
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
около 5 лет назад

During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS3: 4.7
nvd
около 5 лет назад

During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS3: 4.7
debian
около 5 лет назад

During ECDSA signature generation, padding applied in the nonce design ...

CVSS3: 4.7
github
больше 3 лет назад

During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS3: 4.4
fstec
больше 5 лет назад

Уязвимость набора библиотек NSS (Network Security Services), связанная с использованием криптографического алгоритма ECDSA (Elliptic Curve Digital Signature Algorithm), содержащего дефекты, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 22%
0.0007
Низкий

4.4 Medium

CVSS3