[Git][security-tracker-team/security-tracker][master] Add CVE-2020-12401/nss
Salvatore Bonaccorso
carnil at debian.org
Sat Aug 1 07:56:29 BST 2020
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a23ca737 by Salvatore Bonaccorso at 2020-08-01T08:55:54+02:00
Add CVE-2020-12401/nss
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -9548,8 +9548,12 @@ CVE-2020-12402 (During RSA key generation, bignum implementations used a variati
- nss 2:3.53.1-1 (bug #963152)
NOTE: https://hg.mozilla.org/projects/nss/rev/699541a7793bbe9b20f1d73dc49e25c6054aa4c1
NOTE: Fixed upstream in 3.53.1
-CVE-2020-12401
+CVE-2020-12401 [ECDSA timing attack mitigation bypass]
RESERVED
+ - nss 2:3.55-1
+ NOTE: https://hg.mozilla.org/projects/nss/rev/aeb2e583ee957a699d949009c7ba37af76515c20
+ NOTE: https://bugzilla.mozilla.org/show_bug.cgi?id=1631573 (private)
+ NOTE: https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.55_release_notes
CVE-2020-12400 [P-384 and P-521 implementation uses a side-channel vulnerable modular inversion function]
RESERVED
- nss 2:3.55-1
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a23ca7376625be12a0c7a9fec9745f4757a45433
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a23ca7376625be12a0c7a9fec9745f4757a45433
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200801/a5e929fe/attachment.html>
More information about the debian-security-tracker-commits
mailing list