PT-2020-3617 · Mozilla+7 · Firefox For Android+8
Alejandro Cabrera Aldaya
+6
·
Published
2020-06-29
·
Updated
2024-12-12
·
CVE-2020-12401
CVSS v3.1
4.7
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 80
Firefox for Android versions prior to 80
Description
The issue is related to the ECDSA signature generation process, where the removal of padding in the nonce leads to variable-time execution that depends on secret data. This could potentially allow an attacker to gain unauthorized access to protected information. The estimated number of potentially affected devices worldwide is not specified.
Recommendations
For Firefox versions prior to 80, update to version 80 or later to resolve the issue.
For Firefox for Android versions prior to 80, update to version 80 or later to resolve the issue.
Exploit
Fix
Side Channel Attack
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Centos
Firefox
Firefox For Android
Linuxmint
Red Hat
Rocky Linux
Ubuntu