CVE-2020-6829Medium· 5.3▾ SunlitWhen performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about the nonce used during signature generation. Given an electro-magnetic trace of a few signature gener…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.5%
When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about the nonce used during signature generation. Given an electro-magnetic trace of a few signature generations, the private key could have been computed. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
firefox < 80.0firefox_mobile < 80.0Upgrade past the affected range:
firefox 80.0firefox_mobile 80.0Connected by shared product, vendor, weakness, or advisory.
CVE-2020-15664Medium· 6.5By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension
CVE-2020-12401Medium· 4.7During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data
CVE-2020-12400Medium· 4.7When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack
CVE-2020-15670High· 8.8Mozilla developers reported memory safety bugs present in Firefox for Android 79
CVE-2020-15668Medium· 4.3A lock was missing when accessing a data structure and importing certificate information into the trust database
CVE-2020-15666Medium· 6.5When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message