CVE-2020-12402Observable Discrepancy in Mozilla Firefox

Severity
4.4MEDIUMNVD
EPSS
0.1%
top 71.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 9
Latest updateMay 24

Description

During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to record traces leading to the recovery of the secret primes. *Note:* An unmodified Firefox browser does not generate RSA keys in normal operation and is not affected, but products built on top of it might. This vulnerability affects Firefox < 78.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:NExploitability: 0.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5mozilla/firefoxunspecified78
NVDmozilla/firefox< 78.0
Debianmozilla/nss< 2:3.53.1-1+3
NVDopensuse/leap15.1, 15.2+1

Also affects: Debian Linux 9.0, Fedora 32

🔴Vulnerability Details

3
GHSA
GHSA-p7qx-fg8r-mfq9: During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-depen2022-05-24
OSV
CVE-2020-12402: During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-depen2020-07-09
CVEList
CVE-2020-12402: During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-depen2020-07-09

📋Vendor Advisories

9
Oracle
Oracle Oracle Communications Risk Matrix: Core (Apache Commons Compress) — CVE-2019-124022020-10-15
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache Commons Compress) — CVE-2019-124022020-07-15
Ubuntu
NSS vulnerability2020-07-06
Ubuntu
NSS vulnerability2020-07-06
Red Hat
nss: Side channel vulnerabilities during RSA key generation2020-06-02

💬Community

4
Bugzilla
CVE-2020-12402 nss: Side channel vulnerabilities during RSA key generation [fedora-all]2020-06-17
Bugzilla
CVE-2020-12402 nss: Side channel vulnerabilities during RSA key generation2020-04-21
Bugzilla
side channel vulnerabilities during RSA key generation2020-04-20
Bugzilla
Side channel attack on ECDSA signature generation2020-04-20
CVE-2020-12402 — Observable Discrepancy in Mozilla | cvebase