CVE-2018-12404

Name
CVE-2018-12404
Description
A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content. This is a variant of the Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) and affects all NSS versions prior to NSS 3.41.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Issue Tracking https://bugzilla.mozilla.org/show_bug.cgi?id=CVE-2018-12404
Third Party Advisory http://www.securityfocus.com/bid/107260
SUSE http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00021.html
REDHAT https://access.redhat.com/errata/RHSA-2019:2237
MISC https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
MLIST https://lists.debian.org/debian-lts-announce/2020/09/msg00029.html
CONFIRM https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdf
MISC https://us-cert.cisa.gov/ics/advisories/icsa-21-040-04

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:mozilla:network_security_services:*:*:*:*:*:*:*:* network_security_services >= None < 3.41

Vulnerable and fixed packages

Source package Branch Version Maintainer Status