PT-2020-3616 · Mozilla+7 · Firefox For Android+9

Alejandro Cabrera Aldaya

+6

·

Published

2020-07-16

·

Updated

2024-12-12

·

CVE-2020-12400

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 80 Firefox for Android versions prior to 80
Description The issue is related to the modular inversion function in the Network Security Services (NSS) library, which contains defects in cryptographic algorithms. This could allow an attacker to gain unauthorized access to protected information through a possible timing-based side channel attack when converting coordinates from projective to affine.
Recommendations For Firefox versions prior to 80, update to version 80 or later. For Firefox for Android versions prior to 80, update to version 80 or later.

Exploit

Fix

Side Channel Attack

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2482
ALT-PU-2020-2706
ALT-PU-2020-2932
ALT-PU-2020-3442
ALT-PU-2021-1367
ALT-PU-2021-2725
ALT-PU-2021-2881
ALT-PU-2021-3368
ALT-PU-2021-3369
ALT-PU-2022-1781
BDU:2020-03960
CESA-2020_4076
CESA-2021_0538
CVE-2020-12400
DLA-2388-1
DLA-3327-1
MGASA-2020-0318
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
RHSA-2020:4076
RHSA-2020_4076
RHSA-2021:0538
RHSA-2021_0538
RLSA-2021:0538
SUSE-RU-2021:14818-1
SUSE-RU-2021:3115-1
SUSE-RU-2021:3115-2
SUSE-RU-2021:3116-1
USN-4455-1
USN-4474-1
USN-4474-2

Affected Products

Alt Linux
Astra Linux
Centos
Firefox
Firefox For Android
Linuxmint
Network Security Services (Nss) Library
Red Hat
Rocky Linux
Ubuntu