Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Debian 10: DLA-3328-1 Severe curl Security Flaw Risks Code Execution

debian lts
Calendar Grey February 20, 2023
Dist Debian Esm H88
Update your system libraries to mitigate several vulnerabilities identified in the Debian LTS Advisory DLA-3327-2.
Multiple security vulnerabilities have been discovered in nss, the Network Security Service libraries

Summary

When performing EC scalar point multiplication, the wNAF point
multiplication algorithm was used; which leaked partial information about
the nonce used during signature generation. Given an electro-magnetic trace
of a few signature generations, the private key could have been computed.

CVE-2020-12400

When converting coordinates from projective to affine, the modular
inversion was not performed in constant time, resulting in a possible
timing-based side channel attack.

CVE-2020-12401

During ECDSA signature generation, padding applied in the nonce designed to
ensure constant-time scalar multiplication was removed, resulting in
variable-time execution dependent on secret data.

CVE-2020-12403

A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS.
When using multi-part Chacha20, it could cause out-of-bounds reads.
This issue was fixed by explicitly disabling multi-part ChaCha20 

Read the Full Advisory


-------------------------------------------------------------------------Package: nss
Version: 2:3.42.1-1+deb10u6
CVE ID: CVE-2020-6829 CVE-2020-12400 CVE-2020-12401 CVE-2020-12403

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here