An error in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coordinates where it can yield a result `POINT_AT_INFINITY` when it should not. A man-in-the-middle attacker could use this to interfere with a connection, resulting in an attacked party computing an incorrect shared secret.
Name: the Mozilla project
Upstream: Antonio Sanso
Upstream bug report, which is still non-pubic:
Created nss-softokn tracking bugs for this issue:
Affects: fedora-all [bug 1485769]