RE: Vulnerability detected in Mozilla NSS.

"Khandelwal, Kushal" <[email protected]> Tue, 9 Jan 2018 11:56:01 +0000
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
Hello Mozilla Team

We are using Mozilla NSS in our product for TLS 1.2 implementation. Recently our clients have enquired about vulnerability VU#144389 with following description:

Summary : TLS implementations may disclose side channel information via discrepencies between valid and invalid PKCS#1 padding

Link to vulnerability details:
https://www.kb.cert.org/vuls/id/144389


Is Mozilla code affected with this vulnerability?

Thanks
Kushal