CVE-2018-12404
nss - security update
5.9
MEDIUM
CVSS 3.1
EPSS 44.4%
描述
A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content. This is a variant of the Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) and affects all NSS versions prior to NSS 3.41.
如何修補 CVE-2018-12404
要修補 CVE-2018-12404,請將受影響套件升級到下列已修補版本。
- Alpine/nss—升級至 3.41-r0 或更新版本
- —升級至 2:3.41-1 或更新版本
- —升級至 2:3.26-1+debu8u4 或更新版本
- —升級至 2:3.26.2-1.1+deb9u2 或更新版本
CVE-2018-12404 正在被利用嗎?
中等 — EPSS 為 44.4%,可持續追蹤但非最高優先。
受影響套件(4)
- from 0, < 3.41-r0
- from 0, < 2:3.41-1
- from 0, < 2:3.26-1+debu8u4
- from 0, < 2:3.26.2-1.1+deb9u2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |