nss: Information exposure when DH secret are reused across multiple TLS connections
Published Feb 16, 2023
5.9
MEDIUMCVSS 3.1
EPSS 0.59%
Description
The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerability, Firefox disabled support for DHE ciphersuites.
Affected products
-
Affected
- ≥ unspecified, < 78
-
Affected
- ≥ unspecified, < 68.10
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Mozilla | Firefox | unknown | Affected
|
| Mozilla | Firefox ESR | unknown | Affected
|
- < 78.0
- < 68.10.0
No data.
Red Hat Enterprise Linux 5
nss
Out of support scope
Red Hat Enterprise Linux 6
nss
Out of support scope
Red Hat Enterprise Linux 7
nss
Will not fix
Red Hat Enterprise Linux 8
nss
Will not fix
Red Hat Enterprise Linux 9
nss
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | nss | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | nss | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | nss | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | nss | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | nss | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
NSS as shipped with Red Hat Enterprise Linux 6, 7, and 8 does not re-use Diffie-Hellman Ephemeral (DHE) keys. It reuses Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) keys by default, but Attacking ECDH and ECDHE cipher suites are not in the scope of the Raccoon Attack and generally considered to be unaffected [1]. Further, reuse of ECDHE keys can be disabled starting in nss 3.17 [2]. For these reasons, Red Hat Product Security has marked the Severity of this flaw as Low. Please see [3] for more information about Low Severity ratings. 1. https://raccoon-attack.com/RacoonAttack.pdf pg. 13 2. https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.17_release_notes 3. https://access.redhat.com/security/updates/classification
Red Hat mitigation
Any risk involving the ECDHE key reuse on the nss server can be mitigated by setting the SSL_REUSE_SERVER_ECDHE_KEY socket option to PR_FALSE.
References (8)
- https://access.redhat.com/security/cve/CVE-2020-12413 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=CVE-2020-12413 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=1877557 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-4725 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-12413
- https://raccoon-attack.com/ Technical Description
- https://raccoon-attack.com/RacoonAttack.pdf
- https://www.cve.org/CVERecord?id=CVE-2020-12413
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-12413 | Vendor Advisory | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=CVE-2020-12413 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1877557 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-4725 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-12413 | ||
| https://raccoon-attack.com/ | Technical Description | |
| https://raccoon-attack.com/RacoonAttack.pdf | ||
| https://www.cve.org/CVERecord?id=CVE-2020-12413 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data