CVE Database
/

CVE-2020-12402

Back to search

CVE-2020-12402

Published: Jul 9, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to record traces leading to the recovery of the secret primes. *Note:* An unmodified Firefox browser does not generate RSA keys in normal operation and is not affected, but products built on top of it might. This vulnerability affects Firefox < 78.

VendorProductVersions

Mozilla

Firefox

affected
unspecified - < 78

References

openSUSE-SU-2020:0953
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2020:0955
vendor-advisory
x_refsource_SUSE
USN-4417-1
vendor-advisory
x_refsource_UBUNTU
openSUSE-SU-2020:0983
vendor-advisory
x_refsource_SUSE
DSA-4726
vendor-advisory
x_refsource_DEBIAN
FEDORA-2020-3ef1937475
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2020:1017
vendor-advisory
x_refsource_SUSE
GLSA-202007-10
vendor-advisory
x_refsource_GENTOO
USN-4417-2
vendor-advisory
x_refsource_UBUNTU
FEDORA-2020-16741ac7ff
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now