Vulnerability CVE-2020-12400: Information

Description

When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

Severity: MEDIUM (4.7) Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Published: Oct. 8, 2020
Modified: Feb. 20, 2023
Error type identifier: CWE-203

Fixed packages

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:mozilla:firefox:*:*:*:*:*:android:*:*
      End excliding
      80.0

      cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
      End excliding
      80.0