UBUNTU-CVE-2023-6135
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-6135
UBUNTU-CVE-2023-6135
Summary:
Details: Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.
References: https://ubuntu.com/security/CVE-2023-6135, https://www.mozilla.org/en-US/security/advisories/mfsa2023-56/#CVE-2023-6135, https://www.mozilla.org/security/advisories/mfsa2023-56/, https://ubuntu.com/security/notices/USN-6562-1, https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_95.html, https://ubuntu.com/security/notices/USN-6727-1, https://www.cve.org/CVERecord?id=CVE-2023-6135
Affected packages
Package
Name: nss
Purl: pkg:deb/ubuntu/nss@2:3.28.4-0ubuntu0.14.04.5+esm13?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
