The vendor explicitly identifies these products as affected by this CVE.
- nss.src as a component of Red Hat Enterprise Linux 5
- nss as a component of Red Hat Enterprise Linux 6
- nss-devel as a component of Red Hat Enterprise Linux 6
- nss-pkcs11-devel as a component of Red Hat Enterprise Linux 6
- nss-sysinit as a component of Red Hat Enterprise Linux 6
- nss-tools as a component of Red Hat Enterprise Linux 6
- nss.src as a component of Red Hat Enterprise Linux 6
- Summary
- A flaw was found in nss. Using the EM side-channel, it is possible to extract the position of zero and non-zero wNAF digits while nss-certutil tool performs scalar multiplication during the ECDSA signature generation, leaking partial information about the ECDSA nonce. Given a small number of ECDSA signatures, this information can be used to steal the private key. The highest threat from this vulnerability is to data confidentiality.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing this update, applications using NSS or NSPR (for example, Firefox) must be restarted for this update to take effect.
