[GLSA-202007-49] Mozilla Network Security Service (NSS): Information disclosure

Severity Low
Affected Packages 1
Unaffected Packages 1
CVEs 1

NSS has an information disclosure vulnerability when handling DSA keys.

Background
The Mozilla Network Security Service (NSS) is a library implementing
security features like SSL v.2/v.3, TLS, PKCS #5, PKCS #7, PKCS #11, PKCS
#12, S/MIME and X.509 certificates.

Description
NSS was found to not always perform constant-time operations when
working with DSA key material.

Impact
An attacker may be able to obtain information about a DSA private key.

Workaround
There is no known workaround at this time.

Resolution
All NSS users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-libs/nss-3.52.1"

Package Affected Version
pkg:ebuild/dev-libs/nss?distro=gentoo < 3.52.1
Package Unaffected Version
pkg:ebuild/dev-libs/nss?distro=gentoo >= 3.52.1
Source # ID Name URL
CVE CVE-2020-12399 CVE-2020-12399 https://nvd.nist.gov/vuln/detail/CVE-2020-12399
Bugzilla 726842 Bugzilla #726842 https://bugs.gentoo.org/show_bug.cgi?id=726842
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:ebuild/dev-libs/nss?distro=gentoo dev-libs nss < 3.52.1 gentoo
Unaffected pkg:ebuild/dev-libs/nss?distro=gentoo dev-libs nss >= 3.52.1 gentoo
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...