Re: Vulnerability detected in Mozilla NSS.
Frederik Braun <[email protected]> Wed, 10 Jan 2018 10:04:01 +0100
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
I can't speak for the NSS team, but your links points to the ROBOT attack (https://robotattack.org/). Looking at their website and documents, it doesn't seem like they found any issues with NSS. On 09.01.2018 12:56, Khandelwal, Kushal wrote: > Hello Mozilla Team > > We are using Mozilla NSS in our product for TLS 1.2 implementation. Recently our clients have enquired about vulnerability VU#144389 with following description: > > Summary : TLS implementations may disclose side channel information via discrepencies between valid and invalid PKCS#1 padding > > Link to vulnerability details: > https://www.kb.cert.org/vuls/id/144389 > > > Is Mozilla code affected with this vulnerability? > > Thanks > Kushal > > _______________________________________________ > dev-security mailing list > [email protected] > https://lists.mozilla.org/listinfo/dev-security >