Description
When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2388-1 | nss security update |
Debian DLA |
DLA-3327-1 | nss security update |
EUVD |
EUVD-2020-4712 | When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80. |
Ubuntu USN |
USN-4455-1 | NSS vulnerabilities |
Ubuntu USN |
USN-4474-1 | Firefox vulnerabilities |
References
History
Wed, 19 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla firefox Mobile
|
|
| CPEs | cpe:2.3:a:mozilla:firefox_mobile:*:*:*:*:*:android:*:* | |
| Vendors & Products |
Mozilla firefox Mobile
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-04T11:56:52.044Z
Reserved: 2020-04-28T00:00:00.000Z
Link: CVE-2020-12400
No data.
Status : Modified
Published: 2020-10-08T14:15:11.170
Modified: 2026-08-19T15:29:21.807
Link: CVE-2020-12400
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN