Description
When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected products
- Mozilla / Firefoxunspecified – 80
- Mozilla / Firefox80.0
- Mozilla / Firefox for Androidunspecified – 80
- Mozilla / firefox_mobile80.0
Updated 39m ago · 8 sources