Bugzilla – Bug 1119069
VUL-0: CVE-2018-12404: mozilla-nss: nss: Cache side-channel variant of the Bleichenbacher attack
Last modified: 2020-06-16 22:09:45 UTC
rh#1657913 An issue was found in nss before version 3.36.6. The TLS implementation exposes padding oracle in each of the three stages of handling PKCS #1 v1.5 padding References: https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.36.6_release_notes http://cat.eyalro.net/ References: https://bugzilla.redhat.com/show_bug.cgi?id=1657913 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-12404 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12404
This is an autogenerated message for OBS integration: This bug (1119069) was mentioned in https://build.opensuse.org/request/show/657135 15.0+42.3 / mozilla-nss
openSUSE-SU-2018:4117-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1106873,1119069 CVE References: CVE-2018-12384,CVE-2018-12404 Sources used: openSUSE Leap 42.3 (src): mozilla-nss-3.36.6-54.1 openSUSE Leap 15.0 (src): mozilla-nss-3.36.6-lp150.2.6.1
SUSE-SU-2018:4235-1: An update that fixes 9 vulnerabilities is now available. Category: security (important) Bug References: 1097410,1106873,1119069,1119105 CVE References: CVE-2018-0495,CVE-2018-12384,CVE-2018-12404,CVE-2018-12405,CVE-2018-17466,CVE-2018-18492,CVE-2018-18493,CVE-2018-18494,CVE-2018-18498 Sources used: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src): MozillaFirefox-60.4.0-3.21.1 SUSE Linux Enterprise Module for Desktop Applications 15 (src): MozillaFirefox-60.4.0-3.21.1 SUSE Linux Enterprise Module for Basesystem 15 (src): mozilla-nspr-4.20-3.3.2, mozilla-nss-3.40.1-3.7.2
SUSE-SU-2018:4236-1: An update that fixes 9 vulnerabilities is now available. Category: security (important) Bug References: 1097410,1106873,1119069,1119105 CVE References: CVE-2018-0495,CVE-2018-12384,CVE-2018-12404,CVE-2018-12405,CVE-2018-17466,CVE-2018-18492,CVE-2018-18493,CVE-2018-18494,CVE-2018-18498 Sources used: SUSE OpenStack Cloud 7 (src): MozillaFirefox-60.4.0esr-109.55.1, mozilla-nspr-4.20-19.6.1, mozilla-nss-3.40.1-58.18.1 SUSE Linux Enterprise Software Development Kit 12-SP4 (src): MozillaFirefox-60.4.0esr-109.55.1, mozilla-nspr-4.20-19.6.1, mozilla-nss-3.40.1-58.18.1 SUSE Linux Enterprise Software Development Kit 12-SP3 (src): MozillaFirefox-60.4.0esr-109.55.1, mozilla-nspr-4.20-19.6.1, mozilla-nss-3.40.1-58.18.1 SUSE Linux Enterprise Server for SAP 12-SP2 (src): MozillaFirefox-60.4.0esr-109.55.1, mozilla-nspr-4.20-19.6.1, mozilla-nss-3.40.1-58.18.1 SUSE Linux Enterprise Server 12-SP4 (src): MozillaFirefox-60.4.0esr-109.55.1, mozilla-nspr-4.20-19.6.1, mozilla-nss-3.40.1-58.18.1 SUSE Linux Enterprise Server 12-SP3 (src): MozillaFirefox-60.4.0esr-109.55.1, mozilla-nspr-4.20-19.6.1, mozilla-nss-3.40.1-58.18.1 SUSE Linux Enterprise Server 12-SP2-LTSS (src): MozillaFirefox-60.4.0esr-109.55.1, mozilla-nspr-4.20-19.6.1, mozilla-nss-3.40.1-58.18.1 SUSE Linux Enterprise Server 12-SP2-BCL (src): MozillaFirefox-60.4.0esr-109.55.1, mozilla-nspr-4.20-19.6.1, mozilla-nss-3.40.1-58.18.1 SUSE Linux Enterprise Server 12-SP1-LTSS (src): MozillaFirefox-60.4.0esr-109.55.1, mozilla-nspr-4.20-19.6.1, mozilla-nss-3.40.1-58.18.1 SUSE Linux Enterprise Server 12-LTSS (src): MozillaFirefox-60.4.0esr-109.55.1, mozilla-nspr-4.20-19.6.1, mozilla-nss-3.40.1-58.18.1 SUSE Linux Enterprise Desktop 12-SP4 (src): MozillaFirefox-60.4.0esr-109.55.1, mozilla-nspr-4.20-19.6.1, mozilla-nss-3.40.1-58.18.1 SUSE Linux Enterprise Desktop 12-SP3 (src): MozillaFirefox-60.4.0esr-109.55.1, mozilla-nspr-4.20-19.6.1, mozilla-nss-3.40.1-58.18.1 SUSE Enterprise Storage 4 (src): MozillaFirefox-60.4.0esr-109.55.1, mozilla-nspr-4.20-19.6.1, mozilla-nss-3.40.1-58.18.1 SUSE CaaS Platform ALL (src): mozilla-nspr-4.20-19.6.1, mozilla-nss-3.40.1-58.18.1 SUSE CaaS Platform 3.0 (src): mozilla-nspr-4.20-19.6.1, mozilla-nss-3.40.1-58.18.1
SUSE-SU-2019:0273-1: An update that fixes four vulnerabilities is now available. Category: security (important) Bug References: 1119069,1120374,1122983 CVE References: CVE-2018-12404,CVE-2018-18500,CVE-2018-18501,CVE-2018-18505 Sources used: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src): MozillaFirefox-60.5.0-3.24.2 SUSE Linux Enterprise Module for Desktop Applications 15 (src): MozillaFirefox-60.5.0-3.24.2 SUSE Linux Enterprise Module for Basesystem 15 (src): mozilla-nss-3.41.1-3.13.1
openSUSE-SU-2019:0183-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1119069 CVE References: CVE-2018-12404 Sources used: openSUSE Leap 15.0 (src): mozilla-nss-3.41.1-lp150.2.16.1
SUSE-SU-2018:4236-2: An update that fixes 9 vulnerabilities is now available. Category: security (important) Bug References: 1097410,1106873,1119069,1119105 CVE References: CVE-2018-0495,CVE-2018-12384,CVE-2018-12404,CVE-2018-12405,CVE-2018-17466,CVE-2018-18492,CVE-2018-18493,CVE-2018-18494,CVE-2018-18498 Sources used: SUSE Linux Enterprise Server for SAP 12-SP1 (src): MozillaFirefox-60.4.0esr-109.55.1, mozilla-nspr-4.20-19.6.1, mozilla-nss-3.40.1-58.18.1 *** NOTE: This information is not intended to be used for external communication, because this may only be a partial fix. If you have questions please reach out to maintenance coordination.
released
openSUSE-SU-2019:1758-1: An update that fixes four vulnerabilities is now available. Category: security (important) Bug References: 1119069,1120374,1122983 CVE References: CVE-2018-12404,CVE-2018-18500,CVE-2018-18501,CVE-2018-18505 Sources used: openSUSE Leap 15.0 (src): MozillaFirefox-60.8.0-lp150.3.62.1, mozilla-nss-3.41.1-lp150.2.20.1