Description
When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2388-1 | nss security update |
Debian DLA |
DLA-3327-1 | nss security update |
EUVD |
EUVD-2020-4712 | When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80. |
Ubuntu USN |
USN-4455-1 | NSS vulnerabilities |
Ubuntu USN |
USN-4474-1 | Firefox vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-04T11:56:52.044Z
Reserved: 2020-04-28T00:00:00.000Z
Link: CVE-2020-12400
No data.
Status : Modified
Published: 2020-10-08T14:15:11.170
Modified: 2024-11-21T04:59:38.653
Link: CVE-2020-12400
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN