Lucene search

K
prionPRIOn knowledge basePRION:CVE-2014-0076
HistoryMar 25, 2014 - 1:25 p.m.

Design/Logic Flaw

2014-03-2513:25:00
PRIOn knowledge base
www.prio-n.com
11

6.4 Medium

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

17.0%

The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local users to obtain ECDSA nonces via a FLUSH+RELOAD cache side-channel attack.

References