SB2020062105 - Cryptographic issues in firefox (Alpine package)
Published: June 21, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cryptographic issues (CVE-ID: CVE-2020-12402)
The vulnerability allows a remote attacker to recover the secret primes.
During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to record traces leading to the recovery of the secret primes.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=73339ff65b8ac577d3c49b1bae6fe0c5d8cf2e98
- https://git.alpinelinux.org/aports/commit/?id=02f4c40162bc3c2f611ce86613bbf01f13e6146b
- https://git.alpinelinux.org/aports/commit/?id=7ece421265010e81e06c3b8b9137b0b62f7acc73
- https://git.alpinelinux.org/aports/commit/?id=d0f548c93f300779d1813359b060cf641865b16c
- https://git.alpinelinux.org/aports/commit/?id=0ddce5a52e81427c9bb61f4fd23eec1127eae6eb