Lucene search

K
f5F5F5:K15295
HistoryMay 29, 2014 - 12:00 a.m.

K15295 : OpenSSL vulnerability CVE-2014-0076

2014-05-2900:00:00
my.f5.com
50

5.6 Medium

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

17.0%

Security Advisory Description

The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local users to obtain ECDSA nonces via a FLUSH+RELOAD cache side-channel attack.
(
CVE-2014-0076
)
Impact
This vulnerability may allow local users to obtain ECDSA nonces using a FLUSH+RELOAD cache side-channel attack.