Observable discrepancy in Firefox for Android and Mozilla Firefox - CVE-2023-6135

 

Observable discrepancy in Firefox for Android and Mozilla Firefox - CVE-2023-6135

Published: December 19, 2023


Vulnerability identifier: #VU84568
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-6135
CWE-ID: CWE-203
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to a side-channel attack in multiple NSS NIST curves, known as "Minerva". A remote attacker can recover the private key and decrypt data passed between server and client.


Affected software

Firefox for Android
Mozilla Firefox
Amazon Linux AMI
Gentoo Linux
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Ubuntu
openEuler
Fedora
Red Hat OpenShift Serverless
Migration Toolkit for Runtimes
Cryostat
Ansible Automation Platform
OpenShift Logging
Red Hat Migration Toolkit for Applications
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM MQ
IBM Security Verify Governance
OpenShift API for Data Protection (OADP)
Red Hat OpenShift Container Platform
Juniper Secure Analytics (JSA)
Red Hat Single Sign-On
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
flatpak-sdk
flatpak-runtime
nss
nss (Red Hat package)
nss-softokn-devel
nss-tools
nss-sysinit
nss-softokn-freebl-devel
nss-softokn-freebl
nss-util-devel
nss-softokn
nss-devel
nss-util
libnss3 (Ubuntu package)
www-client/firefox
firefox (Ubuntu package)
firefox-flatpak
firefox-debugsource
firefox
firefox-debuginfo
IBM Qradar SIEM
AMQ Broker

How to mitigate CVE-2023-6135

Install updates from vendor's website.

Firefox for Android - update to 121.0
Mozilla Firefox - update to 121.0
Red Hat OpenShift Serverless - update to 1.32.0
Migration Toolkit for Runtimes - update to 1.2.5
OpenShift API for Data Protection (OADP) - update to 1.3.1
Red Hat OpenShift Container Platform - addressed in versions 4.13.34, 4.14.13
Red Hat Migration Toolkit for Applications - addressed in versions 6.2, 7.0.2
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
Red Hat Single Sign-On - update to 7.6.7
flatpak-sdk - update to f39-7
flatpak-runtime - update to f39-16
IBM Cloud Transformation Advisor - update to 3.10.0
Red Hat OpenShift Dev Spaces - update to 3.15.0
nss - update to 3.90.0-6
nss (Red Hat package) - addressed in versions 3.90.0-6.el8_8, 3.90.0-6.el8_9, 3.90.0-6.el9_2, 3.90.0-6.el9_3
nss-softokn-devel - update to 3.90.0-7.0.1
nss-tools - update to 3.90.0-7.0.1
nss-sysinit - update to 3.90.0-7.0.1
nss-softokn-freebl-devel - update to 3.90.0-7.0.1
nss-softokn-freebl - update to 3.90.0-7.0.1
nss-util-devel - update to 3.90.0-7.0.1
nss-softokn - update to 3.90.0-7.0.1
nss-devel - update to 3.90.0-7.0.1
nss - update to 3.90.0-7.0.1
nss-util - update to 3.90.0-7.0.1
libnss3 (Ubuntu package) - addressed in versions 2:3.98-0ubuntu0.20.04.1, 2:3.98-0ubuntu0.20.04.2, 2:3.98-0ubuntu0.22.04.1, 2:3.98-0ubuntu0.22.04.2, 2:3.98-0ubuntu0.23.10.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.4
App Connect Enterprise Certified Container - addressed in versions 5.0.15, 11.3.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF01
AMQ Broker - update to 7.12.0
IBM MQ - addressed in versions 9.3.0.20 FixPack, 9.3.5.2
IBM Security Verify Governance - update to 10.0.2.0.4
www-client/firefox - update to 104
firefox (Ubuntu package) - addressed in versions 121.0+build1-0ubuntu0.20.04.1, 121.0.1+build1-0ubuntu0.20.04.1
firefox-flatpak - update to 121.0-1
firefox-debugsource - update to 128.8.0-1
firefox - update to 128.8.0-1
firefox-debuginfo - update to 128.8.0-1

External References

Related Security Bulletins