[Git][security-tracker-team/security-tracker][master] Add CVE-2020-12401/nss

Salvatore Bonaccorso carnil at debian.org
Sat Aug 1 07:56:29 BST 2020



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a23ca737 by Salvatore Bonaccorso at 2020-08-01T08:55:54+02:00
Add CVE-2020-12401/nss

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -9548,8 +9548,12 @@ CVE-2020-12402 (During RSA key generation, bignum implementations used a variati
 	- nss 2:3.53.1-1 (bug #963152)
 	NOTE: https://hg.mozilla.org/projects/nss/rev/699541a7793bbe9b20f1d73dc49e25c6054aa4c1
 	NOTE: Fixed upstream in 3.53.1
-CVE-2020-12401
+CVE-2020-12401 [ECDSA timing attack mitigation bypass]
 	RESERVED
+	- nss 2:3.55-1
+	NOTE: https://hg.mozilla.org/projects/nss/rev/aeb2e583ee957a699d949009c7ba37af76515c20
+	NOTE: https://bugzilla.mozilla.org/show_bug.cgi?id=1631573 (private)
+	NOTE: https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.55_release_notes
 CVE-2020-12400 [P-384 and P-521 implementation uses a side-channel vulnerable modular inversion function]
 	RESERVED
 	- nss 2:3.55-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a23ca7376625be12a0c7a9fec9745f4757a45433

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a23ca7376625be12a0c7a9fec9745f4757a45433
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200801/a5e929fe/attachment.html>


More information about the debian-security-tracker-commits mailing list