CVE-2020-12403

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-12403
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-12403.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-12403
Related
Published
2021-05-27T19:15:07Z
Modified
2024-09-11T04:32:58.456159Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
[none]
Details

A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.

References

Affected packages

Alpine:v3.12 / nss

Package

Name
nss
Purl
pkg:apk/alpine/nss?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.55-r0

Affected versions

3.*

3.12.6-r0
3.12.7-r0
3.12.8-r0
3.12.8-r1
3.12.8-r2
3.12.8-r3
3.12.8-r4
3.12.8-r5
3.12.8-r6
3.12.9-r0
3.12.10-r0
3.12.11-r0
3.12.11-r1
3.13.1-r0
3.13.1-r1
3.13.3-r0
3.13.4-r0
3.13.4-r1
3.13.5-r0
3.13.6-r0
3.14-r0
3.14.1-r0
3.14.1.1.93-r0
3.14.3-r0
3.15.1-r0
3.15.1-r1
3.15.1-r2
3.15.2-r0
3.15.3-r0
3.15.3.1-r0
3.15.4-r0
3.15.5-r0
3.16-r0
3.16.1-r0
3.16.3-r0
3.17.1-r0
3.17.2-r0
3.17.3-r0
3.17.4-r0
3.18-r0
3.18.1-r0
3.19.2-r0
3.19.2-r1
3.20-r0
3.20.1-r0
3.21-r0
3.22-r0
3.22.1-r0
3.22.3-r0
3.23-r0
3.26-r0
3.27.1-r0
3.27.2-r0
3.28.1-r0
3.28.1-r1
3.30-r0
3.30-r1
3.30-r2
3.30.1-r0
3.31-r0
3.32-r0
3.33-r0
3.34-r0
3.34.1-r0
3.34.1-r1
3.36.1-r0
3.38-r0
3.38-r1
3.39-r0
3.41-r0
3.43-r0
3.43-r1
3.44-r0
3.45-r0
3.46-r0
3.46.1-r0
3.47-r0
3.47.1-r0
3.48-r0
3.49-r0
3.49.1-r0
3.49.2-r0
3.50-r0
3.51-r0
3.51.1-r0
3.52-r0
3.52.1-r0
3.53.1-r0
3.54-r0

Alpine:v3.19 / nss

Package

Name
nss
Purl
pkg:apk/alpine/nss?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.55-r0

Affected versions

3.*

3.12.6-r0
3.12.7-r0
3.12.8-r0
3.12.8-r1
3.12.8-r2
3.12.8-r3
3.12.8-r4
3.12.8-r5
3.12.8-r6
3.12.9-r0
3.12.10-r0
3.12.11-r0
3.12.11-r1
3.13.1-r0
3.13.1-r1
3.13.3-r0
3.13.4-r0
3.13.4-r1
3.13.5-r0
3.13.6-r0
3.14-r0
3.14.1-r0
3.14.1.1.93-r0
3.14.3-r0
3.15.1-r0
3.15.1-r1
3.15.1-r2
3.15.2-r0
3.15.3-r0
3.15.3.1-r0
3.15.4-r0
3.15.5-r0
3.16-r0
3.16.1-r0
3.16.3-r0
3.17.1-r0
3.17.2-r0
3.17.3-r0
3.17.4-r0
3.18-r0
3.18.1-r0
3.19.2-r0
3.19.2-r1
3.20-r0
3.20.1-r0
3.21-r0
3.22-r0
3.22.1-r0
3.22.3-r0
3.23-r0
3.26-r0
3.27.1-r0
3.27.2-r0
3.28.1-r0
3.28.1-r1
3.30-r0
3.30-r1
3.30-r2
3.30.1-r0
3.31-r0
3.32-r0
3.33-r0
3.34-r0
3.34.1-r0
3.34.1-r1
3.36.1-r0
3.38-r0
3.38-r1
3.39-r0
3.41-r0
3.43-r0
3.43-r1
3.44-r0
3.45-r0
3.46-r0
3.46.1-r0
3.47-r0
3.47.1-r0
3.48-r0
3.49-r0
3.49.1-r0
3.49.2-r0
3.50-r0
3.51-r0
3.51.1-r0
3.52-r0
3.52.1-r0
3.53.1-r0
3.54-r0

Alpine:v3.20 / nss

Package

Name
nss
Purl
pkg:apk/alpine/nss?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.55-r0

Affected versions

3.*

3.12.6-r0
3.12.7-r0
3.12.8-r0
3.12.8-r1
3.12.8-r2
3.12.8-r3
3.12.8-r4
3.12.8-r5
3.12.8-r6
3.12.9-r0
3.12.10-r0
3.12.11-r0
3.12.11-r1
3.13.1-r0
3.13.1-r1
3.13.3-r0
3.13.4-r0
3.13.4-r1
3.13.5-r0
3.13.6-r0
3.14-r0
3.14.1-r0
3.14.1.1.93-r0
3.14.3-r0
3.15.1-r0
3.15.1-r1
3.15.1-r2
3.15.2-r0
3.15.3-r0
3.15.3.1-r0
3.15.4-r0
3.15.5-r0
3.16-r0
3.16.1-r0
3.16.3-r0
3.17.1-r0
3.17.2-r0
3.17.3-r0
3.17.4-r0
3.18-r0
3.18.1-r0
3.19.2-r0
3.19.2-r1
3.20-r0
3.20.1-r0
3.21-r0
3.22-r0
3.22.1-r0
3.22.3-r0
3.23-r0
3.26-r0
3.27.1-r0
3.27.2-r0
3.28.1-r0
3.28.1-r1
3.30-r0
3.30-r1
3.30-r2
3.30.1-r0
3.31-r0
3.32-r0
3.33-r0
3.34-r0
3.34.1-r0
3.34.1-r1
3.36.1-r0
3.38-r0
3.38-r1
3.39-r0
3.41-r0
3.43-r0
3.43-r1
3.44-r0
3.45-r0
3.46-r0
3.46.1-r0
3.47-r0
3.47.1-r0
3.48-r0
3.49-r0
3.49.1-r0
3.49.2-r0
3.50-r0
3.51-r0
3.51.1-r0
3.52-r0
3.52.1-r0
3.53.1-r0
3.54-r0

Debian:11 / nss

Package

Name
nss
Purl
pkg:deb/debian/nss?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:3.55-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / nss

Package

Name
nss
Purl
pkg:deb/debian/nss?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:3.55-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / nss

Package

Name
nss
Purl
pkg:deb/debian/nss?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:3.55-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}