Security Advisory

CVE-2020-12399

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-07-09 14:52:16
Last updated 2024-08-04 11:56:51
Assigner mozilla
State PUBLISHED

Description

NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.