Race condition in Mozilla NSS - CVE-2020-12399
Published: June 2, 2020 / Updated: July 15, 2020
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to time differences in Mozilla NSS library during the process of generating a DSA signature, the nonce value 'k' is not padded, exposing the bit length. Combined with other techniques, this can result in the recovery of the DSA private key.
Affected software
Arch Linux
Debian Linux
Gentoo Linux
Oracle Solaris
Slackware Linux
Opensuse
Ubuntu
thunderbird (Debian package)
firefox-esr (Debian package)
firefox (Alpine package)
firefox-esr (Alpine package)
mozjs68 (Alpine package)
thunderbird (Alpine package)
nss (Debian package)
thunderbird (Ubuntu package)
Mozilla Firefox
Firefox ESR
Mozilla Thunderbird
How to mitigate CVE-2020-12399
thunderbird (Debian package) - addressed in versions 1:68.9.0-1~deb9u1, 1:68.9.0-1~deb10u1
Mozilla Firefox - update to 77.0
Firefox ESR - update to 68.9.0
Mozilla Thunderbird - update to 68.9.0
firefox-esr (Debian package) - addressed in versions 68.9.0esr-1~deb9u1, 68.9.0esr-1~deb10u1
firefox (Alpine package) - update to 77.0-r0
firefox-esr (Alpine package) - update to 68.9.0-r0
mozjs68 (Alpine package) - update to 68.9.0-r0
thunderbird (Alpine package) - update to 68.9.0-r0
nss (Debian package) - update to 2:3.42.1-1+deb10u3
thunderbird (Ubuntu package) - addressed in versions 1:68.10.0+build1-0ubuntu0.16.04.1, 1:68.10.0+build1-0ubuntu0.18.04.1, 1:68.10.0+build1-0ubuntu0.19.10.1, 1:68.10.0+build1-0ubuntu0.20.04.1
External References
Related Security Bulletins
- Timing attack in Mozilla NSS library
- Multiple vulnerabilities in Firefox ESR
- Multiple vulnerabilities in Mozilla Firefox
- Arch Linux update for firefox
- Multiple vulnerabilities in Mozilla Thunderbird
- Debian update for firefox-esr
- Slackware Linux update for mozilla-thunderbird
- Arch Linux update for thunderbird
- Debian update for thunderbird
- Oracle Solaris security update for third party software (July 2020)
- Gentoo update for Mozilla Network Security Service (NSS)
- Race condition in thunderbird (Alpine package)
- Race condition in mozjs68 (Alpine package)
- Race condition in firefox-esr (Alpine package)
- Race condition in firefox (Alpine package)
- OpenSUSE Linux update for mozilla-nspr, mozilla-nss
- Debian update for nss
- Ubuntu update for thunderbird