VulnerabilityModified
CVE-2020-12399
NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys.
MEDIUM 4.4EPSS 0.65%
Does this matter?
Lower severity and a low EPSS score (0.65%). Track it; it rarely justifies an emergency change on its own.
Description
NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
- CVSS 3.1
- 4.4 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 0.65% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- mozilla/firefox · mozilla/firefox esr · mozilla/thunderbird · debian/debian linux
- Source
- security@mozilla.org
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1631576Issue Tracking, Permissions Required, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2020/09/msg00029.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202007-49Third Party Advisory
- https://usn.ubuntu.com/4421-1/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4726Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-20/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-21/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-22/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1631576Issue Tracking, Permissions Required, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2020/09/msg00029.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202007-49Third Party Advisory
- https://usn.ubuntu.com/4421-1/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4726Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-20/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-21/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-22/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.