VDB
CVE-2020-12399
CVE-2020-12399
PUBLISHED
NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
EPSS 0.10% · 26.8th percentile
Risk Scores
EPSS Score
0.10%
26.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:20.04:LTS | firefox | 73.0+build1-0ubuntu1, 72.0.2+build1-0ubuntu1, 71.0+build5-0ubuntu1 |
| Ubuntu:18.04:LTS | thunderbird | 1:60.7.0+build1-0ubuntu0.18.04.1, 1:60.5.1+build2-0ubuntu0.18.04.1, 1:60.4.0+build2-0ubuntu0.18.04.1 |
| Ubuntu:20.04:LTS | nss | 0, 2:3.45-1ubuntu2, 2:3.47-1ubuntu2 |
| Ubuntu:16.04:LTS | firefox | *, *, * |
| Ubuntu:Pro:14.04:LTS | nss | *, 0, 2:3.15.1-1ubuntu1 |
| Ubuntu:16.04:LTS | nss | 2:3.23-0ubuntu0.16.04.1, 2:3.21-1ubuntu4, 2:3.21-1ubuntu3 |
| Ubuntu:18.04:LTS | firefox | 70.0.1+build1-0ubuntu0.18.04.1, 70.0+build2-0ubuntu0.18.04.1, 69.0.2+build1-0ubuntu0.18.04.1 |
| Ubuntu:16.04:LTS | thunderbird | 1:52.6.0+build1-0ubuntu0.16.04.1, 1:52.4.0+build1-0ubuntu0.16.04.2, 1:52.2.1+build1-0ubuntu0.16.04.1 |
| Ubuntu:20.04:LTS | thunderbird | 1:68.3.0+build2-0ubuntu1, 1:68.2.2+build1-0ubuntu1, 1:68.2.1+build1-0ubuntu1 |
| Ubuntu:18.04:LTS | nss | *, *, 0 |
Timeline
- May 26, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 22, 2021 EPSS Score
- Aug 23, 2021 EPSS Score
- Oct 24, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 25, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 28, 2022 EPSS Score
- Jun 29, 2022 EPSS Score
- Aug 31, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2020-12399 third-party-advisory
- https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.44.4_release_notes third-party-advisory
- https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.52.1_release_notes third-party-advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2020-20/#CVE-2020-12399 third-party-advisory
- https://ubuntu.com/security/notices/USN-4383-1 vendor-advisory
- https://ubuntu.com/security/notices/USN-4397-1 vendor-advisory
- https://ubuntu.com/security/notices/USN-4397-2 vendor-advisory
- https://ubuntu.com/security/notices/USN-4421-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2020-12399 third-party-advisory