#VU45797 Use of a broken or risky cryptographic algorithm in Mozilla NSS - CVE-2020-12400
Published: August 20, 2020
Mozilla NSS
Mozilla
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists in Mozilla NSS library in the way P-384 and P-521 curves are used in the generation of EDSA signatures, leaking partial information about the ECDSA nonce. Given a small number of ECDSA signatures, this information can be used to steal the private key.