PT-2023-6220 · Mozilla+3 · Network Security Services+3

·

CVE-2023-4421

·

Published

2023-09-13

·

Updated

2026-06-12

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Network Security Services (NSS) versions prior to 3.61
Description The issue is related to the implementation of the PKCS#1 v1.5 standard in the NSS library, which was leaking information useful for mounting Bleichenbacher-like attacks through timing side-channel. This allowed an attacker to decrypt a previously intercepted PKCS#1 v1.5 ciphertext or forge a signature using the victim's key by sending a large number of attacker-selected ciphertexts. The problem was fixed by implementing the implicit rejection algorithm.
Recommendations For versions prior to 3.61, update to version 3.61 or later to resolve the issue. As a temporary workaround, consider implementing the implicit rejection algorithm to return a deterministic random message in case invalid padding is detected. Restrict access to the PKCS#1 v1.5 functionality to minimize the risk of exploitation until the update is applied.

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-06929
CVE-2023-4421
DLA-3634-1
OESA-2026-2612
USN-6727-1
USN-6727-2

Affected Products

Astra Linux
Linuxmint
Network Security Services
Ubuntu