Back

MEDIUM

nss: Information exposure when DH secret are reused across multiple TLS connections

Published Feb 16, 2023

Description

The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerability, Firefox disabled support for DHE ciphersuites.

Affected products

Remediation

Red Hat statement

NSS as shipped with Red Hat Enterprise Linux 6, 7, and 8 does not re-use Diffie-Hellman Ephemeral (DHE) keys. It reuses Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) keys by default, but Attacking ECDH and ECDHE cipher suites are not in the scope of the Raccoon Attack and generally considered to be unaffected [1]. Further, reuse of ECDHE keys can be disabled starting in nss 3.17 [2]. For these reasons, Red Hat Product Security has marked the Severity of this flaw as Low. Please see [3] for more information about Low Severity ratings. 1. https://raccoon-attack.com/RacoonAttack.pdf pg. 13 2. https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.17_release_notes 3. https://access.redhat.com/security/updates/classification

Red Hat mitigation

Any risk involving the ECDHE key reuse on the nss server can be mitigated by setting the SSL_REUSE_SERVER_ECDHE_KEY socket option to PR_FALSE.

Weaknesses (2)

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mozilla
Published Feb 16, 2023
Updated Mar 19, 2025
Reserved Apr 28, 2020

CISA Vulnrichment

Updated Mar 19, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Low
Public date Sep 9, 2020
Bugzilla 1877557

ENISA EUVD

Assigner mozilla
Published Feb 16, 2023
Updated Mar 19, 2025

GitHub

No data