CVE-2020-12399

MEDIUM4.4EPSS 0.09%

firefox-esr - security update

發布日:2020/7/9修改日:2026/4/28
也稱為:DEBIAN-CVE-2020-12399

描述

NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.

受影響套件(6)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM4.4CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N

參考連結(1)