Re: Vulnerability detected in Mozilla NSS.

Frederik Braun <[email protected]> Wed, 10 Jan 2018 10:04:01 +0100
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
I can't speak for the NSS team, but your links points to the ROBOT
attack (https://robotattack.org/).
Looking at their website and documents, it doesn't seem like they found
any issues with NSS.

On 09.01.2018 12:56, Khandelwal, Kushal wrote:
> Hello Mozilla Team
> 
> We are using Mozilla NSS in our product for TLS 1.2 implementation. Recently our clients have enquired about vulnerability VU#144389 with following description:
> 
> Summary : TLS implementations may disclose side channel information via discrepencies between valid and invalid PKCS#1 padding
> 
> Link to vulnerability details:
> https://www.kb.cert.org/vuls/id/144389
> 
> 
> Is Mozilla code affected with this vulnerability?
> 
> Thanks
> Kushal
> 
> _______________________________________________
> dev-security mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-security
>