CVE-2023-6135: Medium severity firefox vulnerability
Last updated 24 July 2024
Other sources
Mozilla Network Security Services (NSS) NIST curves, as used in Mozilla Firefox, could allow a remote attacker to obtain sensitive information, caused by a side-channel attack known as "Minerva". By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to recover private keys.
— IBM
Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key.
— Mozilla
NSS is vulnerable to the Minerva attack https://minerva.crocs.fi.muni.cz/
The CVE has been assigned by upstream.
Upstream bug: https://bugzilla.mozilla.org/showbug.cgi?id=1853908
— Red Hat
Affected Software
Remediation
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-6135?
CVE-2023-6135 is considered high severity due to its potential to allow remote attackers to obtain sensitive information.
How do I fix CVE-2023-6135?
To fix CVE-2023-6135, users should update their Mozilla Firefox and NSS packages to the latest versions that are not affected by this vulnerability.
What systems are affected by CVE-2023-6135?
CVE-2023-6135 affects Mozilla Firefox versions up to 121 and IBM Security Verify Governance components up to ISVG 10.0.2.
Who is at risk from CVE-2023-6135?
Users of the affected versions of Mozilla Firefox and IBM Security Verify Governance are at risk when visiting specially crafted websites.
What type of attack does CVE-2023-6135 involve?
CVE-2023-6135 involves a side-channel attack known as 'Minerva' that could exploit cryptographic vulnerabilities.