Re: Vulnerability Note VU#144389

"J.C. Jones" <[email protected]> Thu, 18 Jan 2018 08:28:57 -0700
Newsgroups gmane.comp.mozilla.security
Message-ID <CAObDDPDC-dUFN4wLqgeZMddKRmLmpHw3smcUn7pZWvzJXnrTFg@mail.gmail.com>
Hi Kushal,

This side-channel, the Robot attack (https://robotattack.org/), wasn't
found to affect NSS.

Cheers,
J.C.

On Wed, Jan 17, 2018 at 5:36 AM, Khandelwal, Kushal <
[email protected]> wrote:

>
> Hello Mozilla Team
>
> We are using Mozilla NSS in our product for TLS 1.2 implementation.
> Recently our clients have enquired about vulnerability VU#144389 with
> following description:
>
> Summary : TLS implementations may disclose side channel information via
> discrepencies between valid and invalid PKCS#1 padding
>
> Link to vulnerability details:
> https://www.kb.cert.org/vuls/id/144389
>
>
> Is Mozilla code affected with this vulnerability?
>
> Thanks
> Kushal
>
> _______________________________________________
> dev-security mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-security
>