CVE-2020-12400
Public on 2020-10-08
Modified on 2021-07-12
Description
A side-channel flaw was found in NSS, in the way P-384 and P-521 curves are used in the generation of EDSA signatures, leaking partial information about the ECDSA nonce. Given a small number of ECDSA signatures, this information can be used to steal the private key. The highest threat from this vulnerability is to data confidentiality.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
HAQM Linux 1 | nspr | 2021-07-08 | ALAS-2021-1522 | Fixed |
HAQM Linux 2 - Core | nspr | 2020-11-09 | ALAS2-2020-1559 | Fixed |
HAQM Linux 2 - Core | nss | 2020-11-09 | ALAS2-2020-1559 | Fixed |
HAQM Linux 1 | nss-softokn | 2021-07-08 | ALAS-2021-1522 | Fixed |
HAQM Linux 2 - Core | nss-softokn | 2020-11-09 | ALAS2-2020-1559 | Fixed |
HAQM Linux 1 | nss-util | 2021-07-08 | ALAS-2021-1522 | Fixed |
HAQM Linux 2 - Core | nss-util | 2020-11-09 | ALAS2-2020-1559 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
HAQM Linux | CVSSv3 | 4.4 | CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N |
NVD | CVSSv2 | 1.2 | AV:L/AC:H/Au:N/C:P/I:N/A:N |
NVD | CVSSv3 | 4.7 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |