Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to CVE-2020-6829. When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about the nonce used during signature generation. Given an electro-magnetic trace of a few signature generations, the private key could have been computed. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
Remediation
There is no fixed version for nss
.
References
CVSS Score
5.3
medium severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityLow
-
IntegrityNone
-
AvailabilityNone
- CVE
- CVE-2020-6829
- Snyk ID
- SNYK-DEBIAN10-NSS-597144
- Disclosed
- 28 Oct, 2020
- Published
- 01 Aug, 2020