Cryptographic issues in Mozilla Firefox - CVE-2020-12402
Published: July 2, 2020 / Updated: July 31, 2020
Vulnerability details
The vulnerability allows a remote attacker to recover the secret primes.
During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to record traces leading to the recovery of the secret primes.
Affected software
Debian Linux
Amazon Linux AMI
Gentoo Linux
F5OS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
CentOS
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
Opensuse
openEuler
Fedora
Ansible Automation Platform
nss (Alpine package)
firefox (Alpine package)
libnss3 (Ubuntu package)
nss (Debian package)
nss-util (Red Hat package)
nss (Red Hat package)
nss-softokn (Red Hat package)
nss
nss-debugsource
nss-util-devel
nss-util
nss-softokn-devel
nss-softokn
nss-debuginfo
nss-devel
nspr (Red Hat package)
nspr
Traffix SDC
Red Hat OpenShift Container Platform
Mozilla Thunderbird
Data Computing Appliance (DCA)
OpenShift Virtualization
How to mitigate CVE-2020-12402
Ansible Automation Platform - addressed in versions 1.0, 1.1, 1.2.4
nss (Alpine package) - update to 3.53.1-r0
Mozilla Thunderbird - addressed in versions 68.10.0, 78.0
firefox (Alpine package) - update to 78.0.1-r0
Data Computing Appliance (DCA) - addressed in versions Firmware tool 3H00, 4.2.1.0
OpenShift Virtualization - update to 2.4.2
libnss3 (Ubuntu package) - addressed in versions 2:3.28.4-0ubuntu0.12.04.9, 2:3.28.4-0ubuntu0.14.04.5+esm6, 2:3.28.4-0ubuntu0.16.04.12, 2:3.35-2ubuntu2.9, 2:3.45-1ubuntu2.4, 2:3.49.1-1ubuntu1.2
nss (Debian package) - update to 2:3.42.1-1+deb10u3
nss-util (Red Hat package) - update to 3.53.1-1.el7_9
nss (Red Hat package) - addressed in versions 3.53.1-3.el7_9, 3.53.1-11.el8_2
nss-softokn (Red Hat package) - update to 3.53.1-6.el7_9
nss - addressed in versions 3.54.0-1.fc31, 3.54.0-1.fc32
nss-debugsource - update to 3.54.0-2
nss-util-devel - update to 3.54.0-2
nss-util - update to 3.54.0-2
nss-softokn-devel - update to 3.54.0-2
nss-softokn - update to 3.54.0-2
nss-debuginfo - update to 3.54.0-2
nss-devel - update to 3.54.0-2
nss - update to 3.54.0-2
Red Hat OpenShift Container Platform - update to 4.3.40
nspr (Red Hat package) - addressed in versions 4.25.0-2.el7_9, 4.25.0-2.el8_2
nspr - addressed in versions 4.26.0-1.fc31, 4.26.0-1.fc32
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox and Firefox ESR
- OpenSUSE Linux update for mozilla-nss
- OpenSUSE Linux update for mozilla-nss
- OpenSUSE Linux update for MozillaFirefox
- OpenSUSE Linux update for MozillaFirefox
- Gentoo update for Mozilla Firefox
- Cryptographic issues in nss (Alpine package)
- Cryptographic issues in firefox (Alpine package)
- Red Hat Enterprise Linux 7 update for nss and nspr
- Multiple vulnerabilities in Mozilla Thunderbird
- Multiple vulnerabilities in NSS component in F5OS and Traffix SDC
- CentOS 7 update for nss
- Amazon Linux AMI update for nspr, nss-softokn, nss-util
- Debian update for nss
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Red Hat Enterprise Linux 8 update for nss and nspr
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 1.2
- openEuler 20.03 LTS update for nss
- Ubuntu update for nss
- Ubuntu update for nss
- Multiple vulnerabilities in OpenShift Virtualization 2.4
- Multiple vulnerabilities in Ansible Automation Platform 1.0 packages
- Multiple vulnerabilities in Ansible Automation Platform 1.1 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.3
- Fedora 32 update for nspr, nss
- Fedora 31 update for nspr, nss