Observable discrepancy in Firefox for Android and Mozilla Firefox - CVE-2023-6135
Published: December 19, 2023
Vulnerability identifier: #VU84568
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-6135
CWE-ID: CWE-203
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to a side-channel attack in multiple NSS NIST curves, known as "Minerva". A remote attacker can recover the private key and decrypt data passed between server and client.
Affected software
Firefox for Android
Mozilla Firefox
Amazon Linux AMI
Gentoo Linux
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Ubuntu
openEuler
Fedora
Red Hat OpenShift Serverless
Migration Toolkit for Runtimes
Cryostat
Ansible Automation Platform
OpenShift Logging
Red Hat Migration Toolkit for Applications
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM MQ
IBM Security Verify Governance
OpenShift API for Data Protection (OADP)
Red Hat OpenShift Container Platform
Juniper Secure Analytics (JSA)
Red Hat Single Sign-On
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
flatpak-sdk
flatpak-runtime
nss
nss (Red Hat package)
nss-softokn-devel
nss-tools
nss-sysinit
nss-softokn-freebl-devel
nss-softokn-freebl
nss-util-devel
nss-softokn
nss-devel
nss-util
libnss3 (Ubuntu package)
www-client/firefox
firefox (Ubuntu package)
firefox-flatpak
firefox-debugsource
firefox
firefox-debuginfo
IBM Qradar SIEM
AMQ Broker
Mozilla Firefox
Amazon Linux AMI
Gentoo Linux
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Ubuntu
openEuler
Fedora
Red Hat OpenShift Serverless
Migration Toolkit for Runtimes
Cryostat
Ansible Automation Platform
OpenShift Logging
Red Hat Migration Toolkit for Applications
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM MQ
IBM Security Verify Governance
OpenShift API for Data Protection (OADP)
Red Hat OpenShift Container Platform
Juniper Secure Analytics (JSA)
Red Hat Single Sign-On
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
flatpak-sdk
flatpak-runtime
nss
nss (Red Hat package)
nss-softokn-devel
nss-tools
nss-sysinit
nss-softokn-freebl-devel
nss-softokn-freebl
nss-util-devel
nss-softokn
nss-devel
nss-util
libnss3 (Ubuntu package)
www-client/firefox
firefox (Ubuntu package)
firefox-flatpak
firefox-debugsource
firefox
firefox-debuginfo
IBM Qradar SIEM
AMQ Broker
How to mitigate CVE-2023-6135
Install updates from vendor's website.
Firefox for Android - update to 121.0
Mozilla Firefox - update to 121.0
Red Hat OpenShift Serverless - update to 1.32.0
Migration Toolkit for Runtimes - update to 1.2.5
OpenShift API for Data Protection (OADP) - update to 1.3.1
Red Hat OpenShift Container Platform - addressed in versions 4.13.34, 4.14.13
Red Hat Migration Toolkit for Applications - addressed in versions 6.2, 7.0.2
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
Red Hat Single Sign-On - update to 7.6.7
flatpak-sdk - update to f39-7
flatpak-runtime - update to f39-16
IBM Cloud Transformation Advisor - update to 3.10.0
Red Hat OpenShift Dev Spaces - update to 3.15.0
nss - update to 3.90.0-6
nss (Red Hat package) - addressed in versions 3.90.0-6.el8_8, 3.90.0-6.el8_9, 3.90.0-6.el9_2, 3.90.0-6.el9_3
nss-softokn-devel - update to 3.90.0-7.0.1
nss-tools - update to 3.90.0-7.0.1
nss-sysinit - update to 3.90.0-7.0.1
nss-softokn-freebl-devel - update to 3.90.0-7.0.1
nss-softokn-freebl - update to 3.90.0-7.0.1
nss-util-devel - update to 3.90.0-7.0.1
nss-softokn - update to 3.90.0-7.0.1
nss-devel - update to 3.90.0-7.0.1
nss - update to 3.90.0-7.0.1
nss-util - update to 3.90.0-7.0.1
libnss3 (Ubuntu package) - addressed in versions 2:3.98-0ubuntu0.20.04.1, 2:3.98-0ubuntu0.20.04.2, 2:3.98-0ubuntu0.22.04.1, 2:3.98-0ubuntu0.22.04.2, 2:3.98-0ubuntu0.23.10.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.4
App Connect Enterprise Certified Container - addressed in versions 5.0.15, 11.3.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF01
AMQ Broker - update to 7.12.0
IBM MQ - addressed in versions 9.3.0.20 FixPack, 9.3.5.2
IBM Security Verify Governance - update to 10.0.2.0.4
www-client/firefox - update to 104
firefox (Ubuntu package) - addressed in versions 121.0+build1-0ubuntu0.20.04.1, 121.0.1+build1-0ubuntu0.20.04.1
firefox-flatpak - update to 121.0-1
firefox-debugsource - update to 128.8.0-1
firefox - update to 128.8.0-1
firefox-debuginfo - update to 128.8.0-1
Mozilla Firefox - update to 121.0
Red Hat OpenShift Serverless - update to 1.32.0
Migration Toolkit for Runtimes - update to 1.2.5
OpenShift API for Data Protection (OADP) - update to 1.3.1
Red Hat OpenShift Container Platform - addressed in versions 4.13.34, 4.14.13
Red Hat Migration Toolkit for Applications - addressed in versions 6.2, 7.0.2
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
Red Hat Single Sign-On - update to 7.6.7
flatpak-sdk - update to f39-7
flatpak-runtime - update to f39-16
IBM Cloud Transformation Advisor - update to 3.10.0
Red Hat OpenShift Dev Spaces - update to 3.15.0
nss - update to 3.90.0-6
nss (Red Hat package) - addressed in versions 3.90.0-6.el8_8, 3.90.0-6.el8_9, 3.90.0-6.el9_2, 3.90.0-6.el9_3
nss-softokn-devel - update to 3.90.0-7.0.1
nss-tools - update to 3.90.0-7.0.1
nss-sysinit - update to 3.90.0-7.0.1
nss-softokn-freebl-devel - update to 3.90.0-7.0.1
nss-softokn-freebl - update to 3.90.0-7.0.1
nss-util-devel - update to 3.90.0-7.0.1
nss-softokn - update to 3.90.0-7.0.1
nss-devel - update to 3.90.0-7.0.1
nss - update to 3.90.0-7.0.1
nss-util - update to 3.90.0-7.0.1
libnss3 (Ubuntu package) - addressed in versions 2:3.98-0ubuntu0.20.04.1, 2:3.98-0ubuntu0.20.04.2, 2:3.98-0ubuntu0.22.04.1, 2:3.98-0ubuntu0.22.04.2, 2:3.98-0ubuntu0.23.10.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.4
App Connect Enterprise Certified Container - addressed in versions 5.0.15, 11.3.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF01
AMQ Broker - update to 7.12.0
IBM MQ - addressed in versions 9.3.0.20 FixPack, 9.3.5.2
IBM Security Verify Governance - update to 10.0.2.0.4
www-client/firefox - update to 104
firefox (Ubuntu package) - addressed in versions 121.0+build1-0ubuntu0.20.04.1, 121.0.1+build1-0ubuntu0.20.04.1
firefox-flatpak - update to 121.0-1
firefox-debugsource - update to 128.8.0-1
firefox - update to 128.8.0-1
firefox-debuginfo - update to 128.8.0-1
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox
- Fedora 39 Flatpaks update for firefox-flatpak, flatpak-runtime, flatpak-sdk
- Ubuntu update for firefox
- Gentoo update for Mozilla Firefox
- Ubuntu update for firefox
- Red Hat Enterprise Linux 8 update for nss
- Red Hat Enterprise Linux 8.8 Extended Update Support update for nss
- Red Hat Enterprise Linux 9 update for nss
- Red Hat Enterprise Linux 9.2 Extended Update Support update for nss
- Multiple vulnerabilities in OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4 for RHEL 9
- Multiple vulnerabilities in Migration Toolkit for Applications 7.0
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Logging Subsystem 5.7 for Red Hat OpenShift for RHEL 8
- Multiple vulnerabilities in Logging Subsystem 5.8 for Red Hat OpenShift for RHEL 9
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6
- Ubuntu update for nss
- Ubuntu update for nss
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in Migration Toolkit for Runtimes 1.2
- Multiple vulnerabilities in Red Hat build of Cryostat 2 on RHEL 8
- Multiple vulnerabilities in AMQ Broker 7.12
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Amazon Linux AMI update for nss
- Multiple vulnerabilities in IBM MQ
- Multiple vulnerabilities in IBM Security Verify Governance - Identity Manager
- openEuler 22.03 LTS SP3 update for firefox
- openEuler 22.03 LTS SP4 update for firefox
- Anolis OS update for nss