NA

CVE-2023-5388

Published: 19/03/2024 Updated: 25/03/2024

Vulnerability Summary

NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an malicious user to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

Vendor Advisories

Debian Bug report logs - #1056284 nss: CVE-2023-5388 Package: src:nss; Maintainer for src:nss is Maintainers of Mozilla-related packages &lt;team+pkg-mozilla@trackerdebianorg&gt;; Reported by: Moritz Mühlenhoff &lt;jmm@inutilorg&gt; Date: Sun, 19 Nov 2023 20:03:02 UTC Severity: important Tags: security, upstream Reply ...
It was discovered that the numerical library used in NSS for RSA cryptography leaks information whether high order bits of the RSA decryption result are zero This information can be used to mount a Bleichenbacher or Manger like attack against all RSA decryption operations As the leak happens before any padding operations, it affects all padding m ...
Synopsis Important: OpenShift Container Platform 41157 bug fix and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 41157 is now available with updates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift ...
Synopsis Important: Red Hat build of Cryostat security update Type/Severity Security Advisory: Important Topic An update is now available for the Red Hat build of Cryostat 2 on RHEL 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a ...
Synopsis Important: OpenShift Container Platform 41410 bug fix and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 41410 is now available with updates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift ...
Synopsis Moderate: Migration Toolkit for Runtimes security, bug fix and enhancement update Type/Severity Security Advisory: Moderate Topic Migration Toolkit for Runtimes 124 releaseRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a de ...
Synopsis Important: OpenShift Container Platform 41329 bug fix and security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat OpenShift Container Platform 413Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) bas ...
Synopsis Moderate: OpenShift Container Platform 4149 bug fix and security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4149 is now available with updates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Con ...
Synopsis Important: OpenShift Container Platform 41247 security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 41247 is now available with updates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Container P ...
Synopsis Moderate: nss security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for nss is now available for Red Hat Enterprise Linux 88 Extended Update SupportRed Hat Product Security has rated this upd ...
Synopsis Moderate: nss security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for nss is now available for Red Hat Enterprise Linux 86 Extended Update SupportRed Hat Product Security has rated this upd ...
Synopsis Moderate: nss security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for nss is now available for Red Hat Enterprise Linux 92 Extended Update SupportRed Hat Product Security has rated this upd ...
Synopsis Moderate: nss security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for nss is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security i ...
It was discovered that the numerical library used in NSS for RSA cryptography leaks information whether high order bits of the RSA decryption result are zero This information can be used to mount a Bleichenbacher or Manger like attack against all RSA decryption operations As the leak happens before any padding operations, it affects all padding m ...
Description<!---->It was discovered that the numerical library used in NSS for RSA cryptography leaks information whether high order bits of the RSA decryption result are zero This information can be used to mount a Bleichenbacher or Manger like attack against all RSA decryption operations As the leak happens before any padding operations, it aff ...
Mozilla Foundation Security Advisory 2024-14 Security Vulnerabilities fixed in Thunderbird 1159 Announced March 19, 2024 Impact high Products Thunderbird Fixed in Thunderbird 1159 ...
Mozilla Foundation Security Advisory 2024-13 Security Vulnerabilities fixed in Firefox ESR 1159 Announced March 19, 2024 Impact high Products Firefox ESR Fixed in Firefox ESR 1159 ...
Mozilla Foundation Security Advisory 2024-12 Security Vulnerabilities fixed in Firefox 124 Announced March 19, 2024 Impact high Products Firefox Fixed in Firefox 124 ...