#VU28522 Race condition in Mozilla NSS - CVE-2020-12399
Published: June 2, 2020 / Updated: July 15, 2020
Mozilla NSS
Mozilla
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to time differences in Mozilla NSS library during the process of generating a DSA signature, the nonce value 'k' is not padded, exposing the bit length. Combined with other techniques, this can result in the recovery of the DSA private key.