[Git][security-tracker-team/security-tracker][master] Add CVE-2018-12404/nss

Salvatore Bonaccorso carnil at debian.org
Tue Dec 11 07:22:44 GMT 2018


Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
fd92cce1 by Salvatore Bonaccorso at 2018-12-11T07:21:15Z
Add CVE-2018-12404/nss

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -23912,8 +23912,13 @@ CVE-2018-12406
 	RESERVED
 CVE-2018-12405
 	RESERVED
-CVE-2018-12404
+CVE-2018-12404 [Cache side-channel variant of the Bleichenbacher attack]
 	RESERVED
+	- nss <unfixed>
+	NOTE: http://cat.eyalro.net/
+	NOTE: https://bugzilla.mozilla.org/show_bug.cgi?id=1485864 (not public)
+	NOTE: https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.36.6_release_notes
+	NOTE: Fixed in 3.36.6, 3.40.1
 CVE-2018-12403
 	RESERVED
 	- firefox 63.0-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/fd92cce1ff7c1ae01a318c1d2a029223ee15ff3a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/fd92cce1ff7c1ae01a318c1d2a029223ee15ff3a
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20181211/e77c2e20/attachment.html>


More information about the debian-security-tracker-commits mailing list