NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | - | 115.9.0 |
| mozilla / thunderbird | - | 115.9.0 |
| mozilla / firefox | - | 124.0 |
| debian / debian_linux | 10.0 | 10.0.x |