CVE-2023-4421
published 2023-12-12CVE-2023-4421: The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mounting Bleichenbacher-like attacks. Both the overall correctness of the padding…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.63%
46.1th percentile
The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mounting Bleichenbacher-like attacks. Both the overall correctness of the padding as well as the length of the encrypted message was leaking through timing side-channel. By sending large number of attacker-selected ciphertexts, the attacker would be able to decrypt a previously intercepted PKCS#1 v1.5 ciphertext (for example, to decrypt a TLS session that used RSA key exchange), or forge a signature using the victim's key. The issue was fixed by implementing the implicit rejection algorithm, in which the NSS returns a deterministic random message in case invalid padding is detected, as proposed in the Marvin Attack paper. This vulnerability affects NSS < 3.61.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nss | < nss 2:3.61-1 (bookworm) | nss 2:3.61-1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | nss | < 3.6.1 | 3.6.1 |
| mozilla | nss | >= 0 < 2:3.61-1 | 2:3.61-1 |
| mozilla | nss | >= 0 < 2:3.61-1 | 2:3.61-1 |
| mozilla | nss | >= 0 < 2:3.61-1 | 2:3.61-1 |
| mozilla | nss | >= 0 < 2:3.61-1 | 2:3.61-1 |
| mozilla | nss | >= 0 < 2:3.98-0ubuntu0.20.04.2 | 2:3.98-0ubuntu0.20.04.2 |
| mozilla | nss | >= 0 < 2:3.98-0ubuntu0.20.04.1 | 2:3.98-0ubuntu0.20.04.1 |
| mozilla | nss | >= 0 < 2:3.98-0ubuntu0.22.04.2 | 2:3.98-0ubuntu0.22.04.2 |
| mozilla | nss | >= 0 < 2:3.98-0ubuntu0.22.04.1 | 2:3.98-0ubuntu0.22.04.1 |
| mozilla | nss | >= unspecified < 3.61 | 3.61 |
| paloalto | pan-os | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
nss regression
osv·2024-04-11·CVSS 6.5
[MEDIUM] nss regression
nss regression
USN-6727-1 fixed vulnerabilities in NSS. The update introduced a regression
when trying to load security modules on Ubuntu 20.04 LTS and Ubuntu 22.04
LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that NSS incorrectly handled padding when checking PKCS#1
certificates. A remote attacker could possibly use this issue to perform
Bleichenbacher-like attacks and recover private data. This issue only
affected Ubuntu 20.04 LTS. (CVE-2023-4421)
It was discovered that NSS had a timing side-channel when performing RSA
decryption. A remote attacker could possibly use this issue to recover
private data. (CVE-2023-5388)
It was discovered that NSS had a timing side-channel when using certain
NIST curves. A remote
OSV
nss vulnerabilities
osv·2024-04-10·CVSS 6.5
CVE-2023-4421 [MEDIUM] nss vulnerabilities
nss vulnerabilities
It was discovered that NSS incorrectly handled padding when checking PKCS#1
certificates. A remote attacker could possibly use this issue to perform
Bleichenbacher-like attacks and recover private data. This issue only
affected Ubuntu 20.04 LTS. (CVE-2023-4421)
It was discovered that NSS had a timing side-channel when performing RSA
decryption. A remote attacker could possibly use this issue to recover
private data. (CVE-2023-5388)
It was discovered that NSS had a timing side-channel when using certain
NIST curves. A remote attacker could possibly use this issue to recover
private data. (CVE-2023-6135)
The NSS package contained outdated CA certificates. This update refreshes
the NSS package to version 3.98 which includes the latest CA certificate
bundle and other se
GHSA
GHSA-3hpv-hgvq-792m: The NSS code used for checking PKCS#1 v1
ghsa_unreviewed·2023-12-12
CVE-2023-4421 [MEDIUM] CWE-203 GHSA-3hpv-hgvq-792m: The NSS code used for checking PKCS#1 v1
The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mounting Bleichenbacher-like attacks. Both the overall correctness of the padding as well as the length of the encrypted message was leaking through timing side-channel. By sending large number of attacker-selected ciphertexts, the attacker would be able to decrypt a previously intercepted PKCS#1 v1.5 ciphertext (for example, to decrypt a TLS session that used RSA key exchange), or forge a signature using the victim's key. The issue was fixed by implementing the implicit rejection algorithm, in which the NSS returns a deterministic random message in case invalid padding is detected, as proposed in the Marvin Attack paper. This vulnerability affects NSS < 3.61.
OSV
CVE-2023-4421: The NSS code used for checking PKCS#1 v1
osv·2023-12-12·CVSS 6.5
CVE-2023-4421 [MEDIUM] CVE-2023-4421: The NSS code used for checking PKCS#1 v1
The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mounting Bleichenbacher-like attacks. Both the overall correctness of the padding as well as the length of the encrypted message was leaking through timing side-channel. By sending large number of attacker-selected ciphertexts, the attacker would be able to decrypt a previously intercepted PKCS#1 v1.5 ciphertext (for example, to decrypt a TLS session that used RSA key exchange), or forge a signature using the victim's key. The issue was fixed by implementing the implicit rejection algorithm, in which the NSS returns a deterministic random message in case invalid padding is detected, as proposed in the Marvin Attack paper. This vulnerability affects NSS < 3.61.
Palo Alto
PAN-SA-2025-0010 Informational Bulletin: No Impact of the Marvin Attack on PAN-OS
vendor_paloalto·2025-05-14·CVSS 5.9
CVE-2024-29995 [MEDIUM] CWE-1240 PAN-SA-2025-0010 Informational Bulletin: No Impact of the Marvin Attack on PAN-OS
PAN-SA-2025-0010 Informational Bulletin: No Impact of the Marvin Attack on PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the applicability of CVEs related to the Marvin attack on PAN-OS. While we did not determine that any of these CVEs have significant impact on our PAN-OS software, some were fixed anyway out of an abundance of caution. You can also review more details about the Marvin attack if helpful. CVE Summary CVE-2024-29995 This CVE does not affect PAN-OS as PAN-OS does not have the vulnerable opensc library. CVE-2024-26306 This CVE does not affect PAN-OS as PAN-OS does not have the vulnerable iperf3 component. CVE-2024-23170 This CVE does not affect PAN-OS as PAN-OS does not have the vulnerable Mbed TLS component. CVE-2024-21484 This CVE does not aff
Ubuntu
NSS regression
vendor_ubuntu·2024-04-11·CVSS 6.5
[MEDIUM] NSS regression
Title: NSS regression
Summary: USN-6727-1 introduced a regression in NSS.
USN-6727-1 fixed vulnerabilities in NSS. The update introduced a regression
when trying to load security modules on Ubuntu 20.04 LTS and Ubuntu 22.04
LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that NSS incorrectly handled padding when checking PKCS#1
certificates. A remote attacker could possibly use this issue to perform
Bleichenbacher-like attacks and recover private data. This issue only
affected Ubuntu 20.04 LTS. (CVE-2023-4421)
It was discovered that NSS had a timing side-channel when performing RSA
decryption. A remote attacker could possibly use this issue to recover
private data. (CVE-2023-5388)
It was discovered that NSS had a t
Ubuntu
NSS vulnerabilities
vendor_ubuntu·2024-04-10·CVSS 6.5
CVE-2023-5388 [MEDIUM] NSS vulnerabilities
Title: NSS vulnerabilities
Summary: Several security issues were fixed in NSS.
It was discovered that NSS incorrectly handled padding when checking PKCS#1
certificates. A remote attacker could possibly use this issue to perform
Bleichenbacher-like attacks and recover private data. This issue only
affected Ubuntu 20.04 LTS. (CVE-2023-4421)
It was discovered that NSS had a timing side-channel when performing RSA
decryption. A remote attacker could possibly use this issue to recover
private data. (CVE-2023-5388)
It was discovered that NSS had a timing side-channel when using certain
NIST curves. A remote attacker could possibly use this issue to recover
private data. (CVE-2023-6135)
The NSS package contained outdated CA certificates. This update refreshes
the NSS package to version 3.98
Red Hat
nss: new tlsfuzzer code can still detect timing issues in RSA operations
vendor_redhat·2023-09-13·CVSS 6.5
CVE-2023-4421 [MEDIUM] CWE-208 nss: new tlsfuzzer code can still detect timing issues in RSA operations
nss: new tlsfuzzer code can still detect timing issues in RSA operations
The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mounting Bleichenbacher-like attacks. Both the overall correctness of the padding as well as the length of the encrypted message was leaking through timing side-channel. By sending large number of attacker-selected ciphertexts, the attacker would be able to decrypt a previously intercepted PKCS#1 v1.5 ciphertext (for example, to decrypt a TLS session that used RSA key exchange), or forge a signature using the victim's key. The issue was fixed by implementing the implicit rejection algorithm, in which the NSS returns a deterministic random message in case invalid padding is detected, as proposed in the Marvin Attack paper. This vulnerability
Debian
CVE-2023-4421: nss - The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mou...
vendor_debian·2023·CVSS 6.5
CVE-2023-4421 [MEDIUM] CVE-2023-4421: nss - The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mou...
The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mounting Bleichenbacher-like attacks. Both the overall correctness of the padding as well as the length of the encrypted message was leaking through timing side-channel. By sending large number of attacker-selected ciphertexts, the attacker would be able to decrypt a previously intercepted PKCS#1 v1.5 ciphertext (for example, to decrypt a TLS session that used RSA key exchange), or forge a signature using the victim's key. The issue was fixed by implementing the implicit rejection algorithm, in which the NSS returns a deterministic random message in case invalid padding is detected, as proposed in the Marvin Attack paper. This vulnerability affects NSS < 3.61.
Scope: local
bookworm: resolved (fixed in 2:3.61-1)
bu
Mozilla
Mozilla Foundation Security Advisory 2023-53: CVE-2023-4421
vendor_mozilla·CVSS 6.5
CVE-2023-4421 [MEDIUM] Mozilla Foundation Security Advisory 2023-53: CVE-2023-4421
Mozilla Foundation Security Advisory 2023-53
CVE: CVE-2023-4421
Product: NSS
Impact: moderate
Fixed in: NSS 3.61
No detection rules found.
No public exploits indexed.
2023-12-12
Published