Re: Vulnerability Note VU#144389
"J.C. Jones" <[email protected]> Thu, 18 Jan 2018 08:28:57 -0700
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CAObDDPDC-dUFN4wLqgeZMddKRmLmpHw3smcUn7pZWvzJXnrTFg@mail.gmail.com> |
Hi Kushal, This side-channel, the Robot attack (https://robotattack.org/), wasn't found to affect NSS. Cheers, J.C. On Wed, Jan 17, 2018 at 5:36 AM, Khandelwal, Kushal < [email protected]> wrote: > > Hello Mozilla Team > > We are using Mozilla NSS in our product for TLS 1.2 implementation. > Recently our clients have enquired about vulnerability VU#144389 with > following description: > > Summary : TLS implementations may disclose side channel information via > discrepencies between valid and invalid PKCS#1 padding > > Link to vulnerability details: > https://www.kb.cert.org/vuls/id/144389 > > > Is Mozilla code affected with this vulnerability? > > Thanks > Kushal > > _______________________________________________ > dev-security mailing list > [email protected] > https://lists.mozilla.org/listinfo/dev-security >