PT-2020-3617 · Mozilla+7 · Firefox For Android+8

Alejandro Cabrera Aldaya

+6

·

Published

2020-06-29

·

Updated

2024-12-12

·

CVE-2020-12401

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 80 Firefox for Android versions prior to 80
Description The issue is related to the ECDSA signature generation process, where the removal of padding in the nonce leads to variable-time execution that depends on secret data. This could potentially allow an attacker to gain unauthorized access to protected information. The estimated number of potentially affected devices worldwide is not specified.
Recommendations For Firefox versions prior to 80, update to version 80 or later to resolve the issue. For Firefox for Android versions prior to 80, update to version 80 or later to resolve the issue.

Exploit

Fix

Side Channel Attack

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2482
ALT-PU-2020-2706
ALT-PU-2020-2932
ALT-PU-2020-3442
ALT-PU-2021-1367
ALT-PU-2021-2725
ALT-PU-2021-2881
ALT-PU-2021-3368
ALT-PU-2021-3369
ALT-PU-2022-1781
BDU:2020-03961
CESA-2020_4076
CESA-2021_0538
CVE-2020-12401
DLA-2388-1
DLA-3327-1
MGASA-2020-0318
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:11058-1
OPENSUSE-SU-2024:14572-1
RHSA-2020:4076
RHSA-2020_4076
RHSA-2021:0538
RHSA-2021_0538
RLSA-2021:0538
SUSE-RU-2021:14818-1
SUSE-RU-2021:3115-1
SUSE-RU-2021:3115-2
SUSE-RU-2021:3116-1
USN-4455-1
USN-4474-1
USN-4474-2

Affected Products

Alt Linux
Astra Linux
Centos
Firefox
Firefox For Android
Linuxmint
Red Hat
Rocky Linux
Ubuntu