NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Firefox | Mozilla | * | 77.0 (excluding) |
Firefox_esr | Mozilla | * | 68.9.0 (excluding) |
Thunderbird | Mozilla | * | 68.9.0 (excluding) |
Red Hat Enterprise Linux 8 | RedHat | nspr-0:4.25.0-2.el8_2 | * |
Red Hat Enterprise Linux 8 | RedHat | nss-0:3.53.1-11.el8_2 | * |
Firefox | Ubuntu | bionic | * |
Firefox | Ubuntu | devel | * |
Firefox | Ubuntu | eoan | * |
Firefox | Ubuntu | focal | * |
Firefox | Ubuntu | trusty | * |
Firefox | Ubuntu | upstream | * |
Firefox | Ubuntu | xenial | * |
Nss | Ubuntu | bionic | * |
Nss | Ubuntu | devel | * |
Nss | Ubuntu | eoan | * |
Nss | Ubuntu | focal | * |
Nss | Ubuntu | trusty | * |
Nss | Ubuntu | trusty/esm | * |
Nss | Ubuntu | upstream | * |
Nss | Ubuntu | xenial | * |
Thunderbird | Ubuntu | bionic | * |
Thunderbird | Ubuntu | devel | * |
Thunderbird | Ubuntu | eoan | * |
Thunderbird | Ubuntu | focal | * |
Thunderbird | Ubuntu | trusty | * |
Thunderbird | Ubuntu | upstream | * |
Thunderbird | Ubuntu | xenial | * |