On Wed, Dec 20, 2023 at 11:43:11AM +0900, Mike Hommey wrote: > Version: 2:3.95-1 > > On Tue, Dec 19, 2023 at 10:21:27PM +0100, Moritz Mühlenhoff wrote: > > Source: nss > > X-Debbugs-CC: t...@security.debian.org > > Severity: grave > > Tags: security > > > > Hi, > > > > The following vulnerability was published for nss. > > > > CVE-2023-6135[0]: > > | Multiple NSS NIST curves were susceptible to a side-channel attack > > | known as "Minerva". This attack could potentially allow an attacker > > | to recover the private key. This vulnerability affects Firefox < > > | 121. > > > > The bug linked from > > https://www.mozilla.org/en-US/security/advisories/mfsa2023-56/#CVE-2023-6135 > > is restricted, do you happen to have a commit reference for NSS itself? > > It was fixed via https://bugzilla.mozilla.org/show_bug.cgi?id=1861728 > and https://bugzilla.mozilla.org/show_bug.cgi?id=1863605, apparently, in > a version that was released last month.
Thanks! Cheers, Moritz