CVE-2023-5388

Source
https://cve.org/CVERecord?id=CVE-2023-5388
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-5388.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-5388
Downstream
ALPINE (1)
BELL (1)
CGA (2)
CLSA (2)
DEBIAN (1)
ECHO (1)
MGASA (3)
OESA (2)
openSUSE (4)
RHSA (23)
RLSA (3)
ROOT (2)
SUSE (10)
UBUNTU (1)
Related
Published
2024-03-19T12:15:07Z
Modified
2026-04-16T04:31:48Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L CVSS Calculator
Summary
[none]
Details

NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-5388.json"
unresolved_ranges
[
    {
        "events":  [
            {
                "introduced":  "0"
            },
            {
                "fixed":  "115.9.0"
            }
        ]
    },
    {
        "events":  [
            {
                "introduced":  "0"
            },
            {
                "fixed":  "124.0"
            }
        ]
    },
    {
        "events":  [
            {
                "introduced":  "0"
            },
            {
                "fixed":  "115.9.0"
            }
        ]
    },
    {
        "events":  [
            {
                "introduced":  "0"
            },
            {
                "last_affected":  "10.0"
            }
        ]
    }
]