VDB

BDU%3A2023-06938

BDU%3A2023-06938 PUBLISHED CVSS 8.5 HIGH

Уязвимость реализации стандартов PKCS#1 v1.5, OAEP и RSASVP набора библиотек NSS (Network Security Services), позволяющая нарушителю реализовать атаку Блейхенбахера (Bleichenbacher) или атаку Марвина (Marvin)

Risk Scores

CVSS 2.0
8.5

Affected Products

VendorProductVersions
Red Hat Inc., Canonical Ltd., ООО «РусБИТех-Астра», Mozilla Corp., АО «ИВК», АО "НППКТ"Red Hat Enterprise Linux, Ubuntu, Astra Linux Special Edition (запись в едином реестре российских программ №369), Network Security Services, АЛЬТ СП 10, Firefox, Firefox ESR, Thunderbird, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913)

Timeline

  • Oct 21, 2023 CVE Published
  • Nov 26, 2024 CVE Updated
  • Mar 19, 2026 Distribution Patch
  • Mar 19, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›