CVE-2018-12404

Publication date 12 December 2018

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

5.9 · Medium

Score breakdown

A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content. This is a variant of the Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) and affects all NSS versions prior to NSS 3.41.

Status

Package Ubuntu Release Status
nss 18.10 cosmic
Fixed 2:3.36.1-1ubuntu1.1
18.04 LTS bionic
Fixed 2:3.35-2ubuntu2.1
16.04 LTS xenial
Fixed 2:3.28.4-0ubuntu0.16.04.4
14.04 LTS trusty
Fixed 2:3.28.4-0ubuntu0.14.04.4

Severity score breakdown

Parameter Value
Base score 5.9 · Medium
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact None
Availability impact None
Vector CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

References

Related Ubuntu Security Notices (USN)

Other references