CVE-2020-12402
published 2020-07-09CVE-2020-12402: During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent…
PriorityP417medium4.4CVSS 3.1
AVLACHPRLUIRSUCHINAN
EPSS
0.34%
26.0th percentile
During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to record traces leading to the recovery of the secret primes. *Note:* An unmodified Firefox browser does not generate RSA keys in normal operation and is not affected, but products built on top of it might. This vulnerability affects Firefox < 78.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | nss | < nss 2:3.53.1-1 (bookworm) | nss 2:3.53.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| mozilla | firefox | < 78.0 | 78.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 78 | 78 |
| mozilla | nss | >= 0 < 2:3.53.1-1 | 2:3.53.1-1 |
| mozilla | nss | >= 0 < 2:3.53.1-1 | 2:3.53.1-1 |
| mozilla | nss | >= 0 < 2:3.53.1-1 | 2:3.53.1-1 |
| mozilla | nss | >= 0 < 2:3.53.1-1 | 2:3.53.1-1 |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
nvdv2.01.2LOWAV:L/AC:H/Au:N/C:P/I:N/A:N
osv4.4MEDIUM
vendor_oracle7.5HIGH
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Core (Apache Commons Compress) — CVE-2019-12402
vendor_oracle·2020-10-15·CVSS 7.5
CVE-2019-12402 [HIGH] Oracle Oracle Communications Risk Matrix: Core (Apache Commons Compress) — CVE-2019-12402
Oracle Oracle Communications Risk Matrix: Core (Apache Commons Compress) vulnerability
CVE: CVE-2019-12402
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache Commons Compress) — CVE-2019-12402
vendor_oracle·2020-07-15·CVSS 7.5
CVE-2019-12402 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache Commons Compress) — CVE-2019-12402
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache Commons Compress) vulnerability
CVE: CVE-2019-12402
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Ubuntu
NSS vulnerability
vendor_ubuntu·2020-07-06
CVE-2020-12402 NSS vulnerability
Title: NSS vulnerability
Summary: NSS could be made to expose sensitive information.
Cesar Pereida, Billy Bob Brumley, Yuval Yarom, and Nicola Tuveri discovered
that NSS incorrectly handled RSA key generation. A local attacker could
possibly use this issue to perform a timing attack and recover RSA keys.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
NSS vulnerability
vendor_ubuntu·2020-07-06
CVE-2020-12402 NSS vulnerability
Title: NSS vulnerability
Summary: NSS could be made to expose sensitive information.
USN-4417-1 fixed a vulnerability in NSS. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
Cesar Pereida, Billy Bob Brumley, Yuval Yarom, and Nicola Tuveri discovered
that NSS incorrectly handled RSA key generation. A local attacker could
possibly use this issue to perform a timing attack and recover RSA keys.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
nss: Side channel vulnerabilities during RSA key generation
vendor_redhat·2020-06-02·CVSS 4.4
CVE-2020-12402 [MEDIUM] CWE-327 nss: Side channel vulnerabilities during RSA key generation
nss: Side channel vulnerabilities during RSA key generation
During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to record traces leading to the recovery of the secret primes. *Note:* An unmodified Firefox browser does not generate RSA keys in normal operation and is not affected, but products built on top of it might. This vulnerability affects Firefox < 78.
A flaw was found in NSS, where it is vulnerable to RSA key generation cache timing side-channel attacks. An attacker with sufficient access to mount cache timing attacks during the RSA key generation process could recover the private key. The h
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Admin (Apache Commons Compress) — CVE-2019-12402
vendor_oracle·2020-04-15·CVSS 7.5
CVE-2019-12402 [HIGH] Oracle Oracle Construction and Engineering Risk Matrix: Admin (Apache Commons Compress) — CVE-2019-12402
Oracle Oracle Construction and Engineering Risk Matrix: Admin (Apache Commons Compress) vulnerability
CVE: CVE-2019-12402
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Debian
CVE-2020-12402: nss - During RSA key generation, bignum implementations used a variation of the Binary...
vendor_debian·2020·CVSS 4.4
CVE-2020-12402 [MEDIUM] CVE-2020-12402: nss - During RSA key generation, bignum implementations used a variation of the Binary...
During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to record traces leading to the recovery of the secret primes. *Note:* An unmodified Firefox browser does not generate RSA keys in normal operation and is not affected, but products built on top of it might. This vulnerability affects Firefox < 78.
Scope: local
bookworm: resolved (fixed in 2:3.53.1-1)
bullseye: resolved (fixed in 2:3.53.1-1)
forky: resolved (fixed in 2:3.53.1-1)
sid: resolved (fixed in 2:3.53.1-1)
trixie: resolved (fixed in 2:3.53.1-1)
Mozilla
Mozilla Foundation Security Advisory 2020-29: CVE-2020-12402
vendor_mozilla·CVSS 4.4
CVE-2020-12402 [MEDIUM] Mozilla Foundation Security Advisory 2020-29: CVE-2020-12402
Mozilla Foundation Security Advisory 2020-29
CVE: CVE-2020-12402
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 78
Mozilla
Mozilla Foundation Security Advisory 2020-24: CVE-2020-12402
vendor_mozilla·CVSS 4.4
CVE-2020-12402 [MEDIUM] Mozilla Foundation Security Advisory 2020-24: CVE-2020-12402
Mozilla Foundation Security Advisory 2020-24
CVE: CVE-2020-12402
Product: Firefox
Impact: high
Fixed in: Firefox 78
GHSA
GHSA-p7qx-fg8r-mfq9: During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-depen
ghsa_unreviewed·2022-05-24
CVE-2020-12402 [MEDIUM] CWE-203 GHSA-p7qx-fg8r-mfq9: During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-depen
During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to record traces leading to the recovery of the secret primes. *Note:* An unmodified Firefox browser does not generate RSA keys in normal operation and is not affected, but products built on top of it might. This vulnerability affects Firefox < 78.
OSV
CVE-2020-12402: During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-depen
osv·2020-07-09·CVSS 4.4
CVE-2020-12402 [MEDIUM] CVE-2020-12402: During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-depen
During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to record traces leading to the recovery of the secret primes. *Note:* An unmodified Firefox browser does not generate RSA keys in normal operation and is not affected, but products built on top of it might. This vulnerability affects Firefox < 78.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-12402 nss: Side channel vulnerabilities during RSA key generation [fedora-all]
bugzilla·2020-06-17·CVSS 4.4
CVE-2020-12402 [MEDIUM] CVE-2020-12402 nss: Side channel vulnerabilities during RSA key generation [fedora-all]
CVE-2020-12402 nss: Side channel vulnerabilities during RSA key generation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2020-12402 nss: Side channel vulnerabilities during RSA key generation
bugzilla·2020-04-21·CVSS 4.4
CVE-2020-12402 [MEDIUM] CVE-2020-12402 nss: Side channel vulnerabilities during RSA key generation
CVE-2020-12402 nss: Side channel vulnerabilities during RSA key generation
It was found that NSS is vulnerable to RSA key generation cache timing side channel attacks. An attacker with sufficient access to mount cache timing attacks during the RSA key generation process could recover the private key.
Discussion:
OpenShift 4.x only packages nss-altfiles and has been confirmed to *not* share any of the vulnerable signature code:
- nss-altfiles only reads information from files in the same format as /etc/passwd and /etc/group.
---
Upstream commit: https://hg.mozilla.org/projects/nss/rev/699541a7793bbe9b20f1d73dc49e25c6054aa4c1
---
External References:
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.53.1_release_notes
---
Created nss tracking bugs for this issue:
Bugzilla
side channel vulnerabilities during RSA key generation
bugzilla·2020-04-20
side channel vulnerabilities during RSA key generation
side channel vulnerabilities during RSA key generation
Created attachment 9141851
nss_rsa_beea.png
[filed from mail to security@ from Billy Brumley]
Hello,
I lead a team of researchers specializes in security and applied
cryptography, in particular both SW and HW-based Side Channel Analysis
(SCA). We recently started a project to assess SCA security in NSS. Part
of that assessment turned up some weaknesses in your implementation of
RSA, led by Nacho (in CC).
Please find the report below -- we look forward to opening a dialogue with
you during the disclosure process.
Billy Brumley, D.Sc. (Tech.)
Associate Professor
Tampere University
Tampere, FINLAND
https://research.tuni.fi/nisec/
## Code path
In the attached debug session (debug.txt), using certutil to generate an
RSA key pair, in
Bugzilla
Side channel attack on ECDSA signature generation
bugzilla·2020-04-20
Side channel attack on ECDSA signature generation
Side channel attack on ECDSA signature generation
Created attachment 9141838
wnaf_trace.jpg
[filed from mail to security@ from Sohaib ul Hassan]
Hey Folks!
We are a team of security researchers from Tampere University, Finland.
We have discovered a vulnerability in ECDSA signature generation that
enables us to exfiltrate information from various side channels and
recover the private key.
# Vulnerable function
The vulnerability is found in the non-constant time ECC scalar
multiplication function ec_GFp_pt_mul_jm_wNAF @
lib/freebl/ecl/ecp_jm.cecp_jm.c. This code path is executed when
either NIST_P384 or NIST_P521 EC curve is selected. The wNAF scalar
multiplication computes EC point doubling (ec_GFp_pt_dbl_jm) at each
iteration, with a conditional branch depending on non-zero scalar
dig
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1631597https://lists.debian.org/debian-lts-announce/2020/09/msg00029.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RFL6UNFK4MG2WDXLMLFAEIUSM5EUK7CG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UWVDJRARXNWWWTCGMM63EXLQHH2LNOXO/https://security.gentoo.org/glsa/202007-10https://usn.ubuntu.com/4417-1/https://usn.ubuntu.com/4417-2/https://www.debian.org/security/2020/dsa-4726https://www.mozilla.org/security/advisories/mfsa2020-24/http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1631597https://lists.debian.org/debian-lts-announce/2020/09/msg00029.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RFL6UNFK4MG2WDXLMLFAEIUSM5EUK7CG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UWVDJRARXNWWWTCGMM63EXLQHH2LNOXO/https://security.gentoo.org/glsa/202007-10https://usn.ubuntu.com/4417-1/https://usn.ubuntu.com/4417-2/https://www.debian.org/security/2020/dsa-4726https://www.mozilla.org/security/advisories/mfsa2020-24/
2020-07-09
Published