PT-2023-6220 · Mozilla+3 · Network Security Services+3
Hubert Kario
·
Published
2023-09-13
·
Updated
2024-04-11
·
CVE-2023-4421
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Network Security Services (NSS) versions prior to 3.61
Description
The issue is related to the implementation of the PKCS#1 v1.5 standard in the NSS library, which was leaking information useful for mounting Bleichenbacher-like attacks through timing side-channel. This allowed an attacker to decrypt a previously intercepted PKCS#1 v1.5 ciphertext or forge a signature using the victim's key by sending a large number of attacker-selected ciphertexts. The problem was fixed by implementing the implicit rejection algorithm.
Recommendations
For versions prior to 3.61, update to version 3.61 or later to resolve the issue. As a temporary workaround, consider implementing the implicit rejection algorithm to return a deterministic random message in case invalid padding is detected. Restrict access to the PKCS#1 v1.5 functionality to minimize the risk of exploitation until the update is applied.
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Network Security Services
Ubuntu