suse · CVE-2018-12404

Quick triage

Priority: medium Published: 2021-05-30 14:14:23 UTC Updated: 2026-04-17 15:23:21 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-12404 severity moderate: SUSE including 537 source package names (1.0.0.1862.1.5.2:libfreebl3-3.41.1-3.13.1, 1.0.0.1862.1.5.2:libsoftokn3-3.41.1-3.13.1, …), 1445 product×package rows across 343 product lines (Container bci/bci-sle15-kernel-module-devel, Container bci/kiwi, … (343 product lines)): Fixed 1147, Known Affected 157, Known Not Affected 141.

Description:

A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content. This is a variant of the Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) and affects all NSS versions prior to NSS 3.41.

cvelogic Threat Intelligence