CVE-2018-12404 Affecting nss package, versions [,3.41)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
2.33% (90th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-NSS-2384895
  • published26 Jan 2022
  • disclosed2 May 2019
  • creditUnknown

Introduced: 2 May 2019

CVE-2018-12404  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade nss to version 3.41 or higher.

Overview

A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content. This is a variant of the Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) and affects all NSS versions prior to NSS 3.41.

CVSS Scores

version 3.1