PT-2020-3616 · Mozilla+7 · Firefox For Android+9
Alejandro Cabrera Aldaya
+6
·
Published
2020-07-16
·
Updated
2024-12-12
·
CVE-2020-12400
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 80
Firefox for Android versions prior to 80
Description
The issue is related to the modular inversion function in the Network Security Services (NSS) library, which contains defects in cryptographic algorithms. This could allow an attacker to gain unauthorized access to protected information through a possible timing-based side channel attack when converting coordinates from projective to affine.
Recommendations
For Firefox versions prior to 80, update to version 80 or later.
For Firefox for Android versions prior to 80, update to version 80 or later.
Exploit
Fix
Side Channel Attack
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Centos
Firefox
Firefox For Android
Linuxmint
Network Security Services (Nss) Library
Red Hat
Rocky Linux
Ubuntu