cbcvebase.
CVE-2023-4421
published 2023-12-12

CVE-2023-4421: The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mounting Bleichenbacher-like attacks. Both the overall correctness of the padding…

PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.63%
46.1th percentile
The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mounting Bleichenbacher-like attacks. Both the overall correctness of the padding as well as the length of the encrypted message was leaking through timing side-channel. By sending large number of attacker-selected ciphertexts, the attacker would be able to decrypt a previously intercepted PKCS#1 v1.5 ciphertext (for example, to decrypt a TLS session that used RSA key exchange), or forge a signature using the victim's key. The issue was fixed by implementing the implicit rejection algorithm, in which the NSS returns a deterministic random message in case invalid padding is detected, as proposed in the Marvin Attack paper. This vulnerability affects NSS < 3.61.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiannss< nss 2:3.61-1 (bookworm)nss 2:3.61-1 (bookworm)
mozillafirefox
mozillanss< 3.6.13.6.1
mozillanss>= 0 < 2:3.61-12:3.61-1
mozillanss>= 0 < 2:3.61-12:3.61-1
mozillanss>= 0 < 2:3.61-12:3.61-1
mozillanss>= 0 < 2:3.61-12:3.61-1
mozillanss>= 0 < 2:3.98-0ubuntu0.20.04.22:3.98-0ubuntu0.20.04.2
mozillanss>= 0 < 2:3.98-0ubuntu0.20.04.12:3.98-0ubuntu0.20.04.1
mozillanss>= 0 < 2:3.98-0ubuntu0.22.04.22:3.98-0ubuntu0.22.04.2
mozillanss>= 0 < 2:3.98-0ubuntu0.22.04.12:3.98-0ubuntu0.22.04.1
mozillanss>= unspecified < 3.613.61
paloaltopan-os

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.