CVE-2023-6135
published 2023-12-19CVE-2023-6135: Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private…
medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 121.0-1 (sid) | firefox 121.0-1 (sid) |
| debian | nss | < firefox 121.0-1 (sid) | firefox 121.0-1 (sid) |
| mozilla | firefox | < 121.0 | 121.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 121.0+build1-0ubuntu0.20.04.1 | 121.0+build1-0ubuntu0.20.04.1 |
| mozilla | firefox | >= 0 < 121.0.1+build1-0ubuntu0.20.04.1 | 121.0.1+build1-0ubuntu0.20.04.1 |
| mozilla | firefox | >= unspecified < 121 | 121 |
| mozilla | nss | >= 0 < 2:3.95-1 | 2:3.95-1 |
| mozilla | nss | >= 0 < 2:3.95-1 | 2:3.95-1 |
| mozilla | nss | >= 0 < 2:3.98-0ubuntu0.20.04.2 | 2:3.98-0ubuntu0.20.04.2 |
| mozilla | nss | >= 0 < 2:3.98-0ubuntu0.20.04.1 | 2:3.98-0ubuntu0.20.04.1 |
| mozilla | nss | >= 0 < 2:3.98-0ubuntu0.22.04.2 | 2:3.98-0ubuntu0.22.04.2 |
| mozilla | nss | >= 0 < 2:3.98-0ubuntu0.22.04.1 | 2:3.98-0ubuntu0.22.04.1 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
osv6.5MEDIUM
OSV
nss regression
osv·2024-04-11·CVSS 6.5
[MEDIUM] nss regression
nss regression
USN-6727-1 fixed vulnerabilities in NSS. The update introduced a regression
when trying to load security modules on Ubuntu 20.04 LTS and Ubuntu 22.04
LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that NSS incorrectly handled padding when checking PKCS#1
certificates. A remote attacker could possibly use this issue to perform
Bleichenbacher-like attacks and recover private data. This issue only
affected Ubuntu 20.04 LTS. (CVE-2023-4421)
It was discovered that NSS had a timing side-channel when performing RSA
decryption. A remote attacker could possibly use this issue to recover
private data. (CVE-2023-5388)
It was discovered that NSS had a timing side-channel when using certain
NIST curves. A remote
OSV
nss vulnerabilities
osv·2024-04-10·CVSS 6.5
CVE-2023-4421 [MEDIUM] nss vulnerabilities
nss vulnerabilities
It was discovered that NSS incorrectly handled padding when checking PKCS#1
certificates. A remote attacker could possibly use this issue to perform
Bleichenbacher-like attacks and recover private data. This issue only
affected Ubuntu 20.04 LTS. (CVE-2023-4421)
It was discovered that NSS had a timing side-channel when performing RSA
decryption. A remote attacker could possibly use this issue to recover
private data. (CVE-2023-5388)
It was discovered that NSS had a timing side-channel when using certain
NIST curves. A remote attacker could possibly use this issue to recover
private data. (CVE-2023-6135)
The NSS package contained outdated CA certificates. This update refreshes
the NSS package to version 3.98 which includes the latest CA certificate
bundle and other se
OSV
firefox regressions
osv·2024-01-11·CVSS 4.3
CVE-2023-6865 [MEDIUM] firefox regressions
firefox regressions
USN-6562-1 fixed vulnerabilities in Firefox. The update introduced
several minor regressions. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code.(CVE-2023-6865,
CVE-2023-6857, CVE-2023-6858, CVE-2023-6859, CVE-2023-6866, CVE-2023-6867,
CVE-2023-6861, CVE-2023-6869, CVE-2023-6871, CVE-2023-6872, CVE-2023-6863,
CVE-2023-6864, CVE-2023-6873)
DoHyun Lee discovered that Firefox did not properly manage memory when used
on systems with the Mesa VM driver. An attacker coul
OSV
firefox vulnerabilities
osv·2024-01-02·CVSS 4.3
CVE-2023-6865 [MEDIUM] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code.(CVE-2023-6865,
CVE-2023-6857, CVE-2023-6858, CVE-2023-6859, CVE-2023-6866, CVE-2023-6867,
CVE-2023-6861, CVE-2023-6869, CVE-2023-6871, CVE-2023-6872, CVE-2023-6863,
CVE-2023-6864, CVE-2023-6873)
DoHyun Lee discovered that Firefox did not properly manage memory when used
on systems with the Mesa VM driver. An attacker could potentially exploit
this issue to execute arbitrary code. (CVE-2023-6856)
George Pantela and Hubert Kario discovered that Firefox using multiple NSS
NIST curves which were susceptible
OSV
CVE-2023-6135: Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva"
osv·2023-12-19·CVSS 4.3
CVE-2023-6135 [MEDIUM] CVE-2023-6135: Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva"
Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.
GHSA
GHSA-jxv6-m6pm-cqh2: Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva"
ghsa_unreviewed·2023-12-19
CVE-2023-6135 [MEDIUM] CWE-203 GHSA-jxv6-m6pm-cqh2: Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva"
Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.
Ubuntu
NSS regression
vendor_ubuntu·2024-04-11·CVSS 6.5
[MEDIUM] NSS regression
Title: NSS regression
Summary: USN-6727-1 introduced a regression in NSS.
USN-6727-1 fixed vulnerabilities in NSS. The update introduced a regression
when trying to load security modules on Ubuntu 20.04 LTS and Ubuntu 22.04
LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that NSS incorrectly handled padding when checking PKCS#1
certificates. A remote attacker could possibly use this issue to perform
Bleichenbacher-like attacks and recover private data. This issue only
affected Ubuntu 20.04 LTS. (CVE-2023-4421)
It was discovered that NSS had a timing side-channel when performing RSA
decryption. A remote attacker could possibly use this issue to recover
private data. (CVE-2023-5388)
It was discovered that NSS had a t
Ubuntu
NSS vulnerabilities
vendor_ubuntu·2024-04-10·CVSS 6.5
CVE-2023-5388 [MEDIUM] NSS vulnerabilities
Title: NSS vulnerabilities
Summary: Several security issues were fixed in NSS.
It was discovered that NSS incorrectly handled padding when checking PKCS#1
certificates. A remote attacker could possibly use this issue to perform
Bleichenbacher-like attacks and recover private data. This issue only
affected Ubuntu 20.04 LTS. (CVE-2023-4421)
It was discovered that NSS had a timing side-channel when performing RSA
decryption. A remote attacker could possibly use this issue to recover
private data. (CVE-2023-5388)
It was discovered that NSS had a timing side-channel when using certain
NIST curves. A remote attacker could possibly use this issue to recover
private data. (CVE-2023-6135)
The NSS package contained outdated CA certificates. This update refreshes
the NSS package to version 3.98
Ubuntu
Firefox regressions
vendor_ubuntu·2024-01-11·CVSS 4.3
[MEDIUM] Firefox regressions
Title: Firefox regressions
Summary: USN-6562-1 caused some minor regressions in Firefox.
USN-6562-1 fixed vulnerabilities in Firefox. The update introduced
several minor regressions. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code.(CVE-2023-6865,
CVE-2023-6857, CVE-2023-6858, CVE-2023-6859, CVE-2023-6866, CVE-2023-6867,
CVE-2023-6861, CVE-2023-6869, CVE-2023-6871, CVE-2023-6872, CVE-2023-6863,
CVE-2023-6864, CVE-2023-6873)
DoHyun Lee discovered that Firefox did not properly manage
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2024-01-02·CVSS 4.3
CVE-2023-6857 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code.(CVE-2023-6865,
CVE-2023-6857, CVE-2023-6858, CVE-2023-6859, CVE-2023-6866, CVE-2023-6867,
CVE-2023-6861, CVE-2023-6869, CVE-2023-6871, CVE-2023-6872, CVE-2023-6863,
CVE-2023-6864, CVE-2023-6873)
DoHyun Lee discovered that Firefox did not properly manage memory when used
on systems with the Mesa VM driver. An attacker could potentially exploit
this issue to execute arbitrary code. (CVE-2023-6856)
George Pantela and Hubert Kario discovered tha
Red Hat
nss: vulnerable to Minerva side-channel information leak
vendor_redhat·2023-12-19·CVSS 4.3
CVE-2023-6135 [MEDIUM] CWE-200 nss: vulnerable to Minerva side-channel information leak
nss: vulnerable to Minerva side-channel information leak
Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.
The Network Security Services (NSS) package contains a vulnerability that exposes a side-channel information leak. This weakness enables a local attacker to capture several thousand usages of a signature, allowing them to utilize this information to recover portions of an ECDSA private key.
Statement: The severity of the Network Security Services (NSS) package vulnerability is marked as moderate due to the inherent risk associated with a potential side-channel information leak. This flaw empowers a local attacker to capture a sub
Debian
CVE-2023-6135: firefox - Multiple NSS NIST curves were susceptible to a side-channel attack known as "Min...
vendor_debian·2023·CVSS 4.3
CVE-2023-6135 [MEDIUM] CVE-2023-6135: firefox - Multiple NSS NIST curves were susceptible to a side-channel attack known as "Min...
Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.
Scope: local
sid: resolved (fixed in 121.0-1)
Mozilla
Mozilla Foundation Security Advisory 2023-56: CVE-2023-6135
vendor_mozilla·CVSS 4.3
CVE-2023-6135 [MEDIUM] Mozilla Foundation Security Advisory 2023-56: CVE-2023-6135
Mozilla Foundation Security Advisory 2023-56
CVE: CVE-2023-6135
Product: Firefox
Impact: high
Fixed in: Firefox 121
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1853908https://security.gentoo.org/glsa/202401-10https://www.mozilla.org/security/advisories/mfsa2023-56/https://bugzilla.mozilla.org/show_bug.cgi?id=1853908https://security.gentoo.org/glsa/202401-10https://www.mozilla.org/security/advisories/mfsa2023-56/
2023-12-19
Published