Lucene search

K
redhatcveRedhat.comRH:CVE-2020-6829
HistoryJul 31, 2020 - 8:13 a.m.

CVE-2020-6829

2020-07-3108:13:18
redhat.com
access.redhat.com
14

0.001 Low

EPSS

Percentile

45.7%

A flaw was found in nss. Using the EM side-channel, it is possible to extract the position of zero and non-zero wNAF digits while nss-certutil tool performs scalar multiplication during the ECDSA signature generation, leaking partial information about the ECDSA nonce. Given a small number of ECDSA signatures, this information can be used to steal the private key. The highest threat from this vulnerability is to data confidentiality.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.