Description
When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about the nonce used during signature generation. Given an electro-magnetic trace of a few signature generations, the private key could have been computed. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2388-1 | nss security update |
Debian DLA |
DLA-3327-1 | nss security update |
EUVD |
EUVD-2020-27973 | When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about the nonce used during signature generation. Given an electro-magnetic trace of a few signature generations, the private key could have been computed. This vulnerability affects Firefox < 80 and Firefox for Android < 80. |
Ubuntu USN |
USN-4455-1 | NSS vulnerabilities |
Ubuntu USN |
USN-4474-1 | Firefox vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-04T09:11:05.159Z
Reserved: 2020-01-10T00:00:00.000Z
Link: CVE-2020-6829
No data.
Status : Modified
Published: 2020-10-28T12:15:12.407
Modified: 2024-11-21T05:36:15.183
Link: CVE-2020-6829
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN