Cryptographic issues in Mozilla Firefox - CVE-2020-12402

 

Cryptographic issues in Mozilla Firefox - CVE-2020-12402

Published: July 2, 2020 / Updated: July 31, 2020


Vulnerability identifier: #VU29460
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12402
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to recover the secret primes.

During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to record traces leading to the recovery of the secret primes.


Affected software

Mozilla Firefox
Debian Linux
Amazon Linux AMI
Gentoo Linux
F5OS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
CentOS
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
Opensuse
openEuler
Fedora
Ansible Automation Platform
nss (Alpine package)
firefox (Alpine package)
libnss3 (Ubuntu package)
nss (Debian package)
nss-util (Red Hat package)
nss (Red Hat package)
nss-softokn (Red Hat package)
nss
nss-debugsource
nss-util-devel
nss-util
nss-softokn-devel
nss-softokn
nss-debuginfo
nss-devel
nspr (Red Hat package)
nspr
Traffix SDC
Red Hat OpenShift Container Platform
Mozilla Thunderbird
Data Computing Appliance (DCA)
OpenShift Virtualization

How to mitigate CVE-2020-12402

Install updates from vendor's website.

Mozilla Firefox - update to 78.0.1
Ansible Automation Platform - addressed in versions 1.0, 1.1, 1.2.4
nss (Alpine package) - update to 3.53.1-r0
Mozilla Thunderbird - addressed in versions 68.10.0, 78.0
firefox (Alpine package) - update to 78.0.1-r0
Data Computing Appliance (DCA) - addressed in versions Firmware tool 3H00, 4.2.1.0
OpenShift Virtualization - update to 2.4.2
libnss3 (Ubuntu package) - addressed in versions 2:3.28.4-0ubuntu0.12.04.9, 2:3.28.4-0ubuntu0.14.04.5+esm6, 2:3.28.4-0ubuntu0.16.04.12, 2:3.35-2ubuntu2.9, 2:3.45-1ubuntu2.4, 2:3.49.1-1ubuntu1.2
nss (Debian package) - update to 2:3.42.1-1+deb10u3
nss-util (Red Hat package) - update to 3.53.1-1.el7_9
nss (Red Hat package) - addressed in versions 3.53.1-3.el7_9, 3.53.1-11.el8_2
nss-softokn (Red Hat package) - update to 3.53.1-6.el7_9
nss - addressed in versions 3.54.0-1.fc31, 3.54.0-1.fc32
nss-debugsource - update to 3.54.0-2
nss-util-devel - update to 3.54.0-2
nss-util - update to 3.54.0-2
nss-softokn-devel - update to 3.54.0-2
nss-softokn - update to 3.54.0-2
nss-debuginfo - update to 3.54.0-2
nss-devel - update to 3.54.0-2
nss - update to 3.54.0-2
Red Hat OpenShift Container Platform - update to 4.3.40
nspr (Red Hat package) - addressed in versions 4.25.0-2.el7_9, 4.25.0-2.el8_2
nspr - addressed in versions 4.26.0-1.fc31, 4.26.0-1.fc32

External References

Related Security Bulletins