UBUNTU-CVE-2023-5388
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-5388
UBUNTU-CVE-2023-5388
Summary:
Details: NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
References: https://ubuntu.com/security/CVE-2023-5388, https://people.redhat.com/~hkario/marvin/, https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_98.html, https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_90_2.html, https://ubuntu.com/security/notices/USN-6703-1, https://ubuntu.com/security/notices/USN-6717-1, https://ubuntu.com/security/notices/USN-6727-1, https://www.cve.org/CVERecord?id=CVE-2023-5388
Affected packages
Package
Name: nss
Purl: pkg:deb/ubuntu/nss@2:3.28.4-0ubuntu0.14.04.5+esm13?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
