Race condition in Mozilla NSS - CVE-2020-12399

 

Race condition in Mozilla NSS - CVE-2020-12399

Published: June 2, 2020 / Updated: July 15, 2020


Vulnerability identifier: #VU28522
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12399
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to time differences in Mozilla NSS library during the process of generating a DSA signature, the nonce value 'k' is not padded, exposing the bit length. Combined with other techniques, this can result in the recovery of the DSA private key.


Affected software

Mozilla NSS
Arch Linux
Debian Linux
Gentoo Linux
Oracle Solaris
Slackware Linux
Opensuse
Ubuntu
thunderbird (Debian package)
firefox-esr (Debian package)
firefox (Alpine package)
firefox-esr (Alpine package)
mozjs68 (Alpine package)
thunderbird (Alpine package)
nss (Debian package)
thunderbird (Ubuntu package)
Mozilla Firefox
Firefox ESR
Mozilla Thunderbird

How to mitigate CVE-2020-12399

Install updates from vendor's website.

Mozilla NSS - addressed in versions 3.44.4, 3.53
thunderbird (Debian package) - addressed in versions 1:68.9.0-1~deb9u1, 1:68.9.0-1~deb10u1
Mozilla Firefox - update to 77.0
Firefox ESR - update to 68.9.0
Mozilla Thunderbird - update to 68.9.0
firefox-esr (Debian package) - addressed in versions 68.9.0esr-1~deb9u1, 68.9.0esr-1~deb10u1
firefox (Alpine package) - update to 77.0-r0
firefox-esr (Alpine package) - update to 68.9.0-r0
mozjs68 (Alpine package) - update to 68.9.0-r0
thunderbird (Alpine package) - update to 68.9.0-r0
nss (Debian package) - update to 2:3.42.1-1+deb10u3
thunderbird (Ubuntu package) - addressed in versions 1:68.10.0+build1-0ubuntu0.16.04.1, 1:68.10.0+build1-0ubuntu0.18.04.1, 1:68.10.0+build1-0ubuntu0.19.10.1, 1:68.10.0+build1-0ubuntu0.20.04.1

External References

Related Security Bulletins