CVE-2018-12404
Public on 2019-05-02
Modified on 2020-03-18
Description
A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content. This is a variant of the Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) and affects all NSS versions prior to NSS 3.41.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 1 | nspr | 2020-03-16 | ALAS-2020-1355 | Fixed |
Amazon Linux 1 | nss | 2020-03-16 | ALAS-2020-1355 | Fixed |
Amazon Linux 2 - Core | nss | 2019-09-30 | ALAS2-2019-1305 | Fixed |
Amazon Linux 1 | nss-softokn | 2020-03-16 | ALAS-2020-1355 | Fixed |
Amazon Linux 1 | nss-util | 2020-03-16 | ALAS-2020-1355 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 5.9 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
NVD | CVSSv2 | 4.3 | AV:N/AC:M/Au:N/C:P/I:N/A:N |
NVD | CVSSv3 | 5.9 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |