CVE-2014-0076

N/A Unknown
Published: March 25, 2014 Modified: May 06, 2026
View on NVD

Description

The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local users to obtain ECDSA nonces via a FLUSH+RELOAD cache side-channel attack.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://eprint.iacr.org/2014/140
Source: secalert@redhat.com
http://secunia.com/advisories/58492
Source: secalert@redhat.com
http://secunia.com/advisories/58727
Source: secalert@redhat.com
http://secunia.com/advisories/58939
Source: secalert@redhat.com
http://secunia.com/advisories/59040
Source: secalert@redhat.com
http://secunia.com/advisories/59162
Source: secalert@redhat.com
http://secunia.com/advisories/59175
Source: secalert@redhat.com
http://secunia.com/advisories/59264
Source: secalert@redhat.com
http://secunia.com/advisories/59300
Source: secalert@redhat.com
http://secunia.com/advisories/59364
Source: secalert@redhat.com
http://secunia.com/advisories/59374
Source: secalert@redhat.com
http://secunia.com/advisories/59413
Source: secalert@redhat.com
http://secunia.com/advisories/59438
Source: secalert@redhat.com
http://secunia.com/advisories/59445
Source: secalert@redhat.com
http://secunia.com/advisories/59450
Source: secalert@redhat.com
http://secunia.com/advisories/59454
Source: secalert@redhat.com
http://secunia.com/advisories/59490
Source: secalert@redhat.com
http://secunia.com/advisories/59495
Source: secalert@redhat.com
http://secunia.com/advisories/59514
Source: secalert@redhat.com
http://secunia.com/advisories/59655
Source: secalert@redhat.com
http://secunia.com/advisories/59721
Source: secalert@redhat.com
http://secunia.com/advisories/60571
Source: secalert@redhat.com
http://support.apple.com/kb/HT6443
Source: secalert@redhat.com
http://www.securityfocus.com/bid/66363
Source: secalert@redhat.com
http://www.ubuntu.com/usn/USN-2165-1
Source: secalert@redhat.com
http://advisories.mageia.org/MGASA-2014-0165.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://eprint.iacr.org/2014/140
Source: af854a3a-2127-422b-91ae-364da2661108
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10629
Source: af854a3a-2127-422b-91ae-364da2661108
http://lists.opensuse.org/opensuse-updates/2014-04/msg00007.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=140266410314613&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=140317760000786&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=140389274407904&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=140389355508263&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=140448122410568&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=140482916501310&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=140621259019789&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=140752315422991&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=140904544427729&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/58492
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/58727
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/58939
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59040
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59162
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59175
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59264
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59300
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59364
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59374
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59413
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59438
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59445
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59450
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59454
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59490
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59495
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59514
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59655
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59721
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/60571
Source: af854a3a-2127-422b-91ae-364da2661108
http://support.apple.com/kb/HT6443
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=isg400001841
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=isg400001843
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=swg21673137
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=swg21676035
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=swg21676062
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=swg21676092
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=swg21676419
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=swg21676424
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=swg21676501
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=swg21676655
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=swg21677695
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=swg21677828
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDVSA-2014:067
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDVSA-2015:062
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.novell.com/support/kb/doc.php?id=7015264
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.novell.com/support/kb/doc.php?id=7015300
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.openssl.org/news/secadv_20140605.txt
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/66363
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/USN-2165-1
Source: af854a3a-2127-422b-91ae-364da2661108
https://bugs.gentoo.org/show_bug.cgi?id=505278
Source: af854a3a-2127-422b-91ae-364da2661108
https://bugzilla.novell.com/show_bug.cgi?id=869945
Source: af854a3a-2127-422b-91ae-364da2661108
https://kc.mcafee.com/corporate/index?page=content&id=SB10075
Source: af854a3a-2127-422b-91ae-364da2661108

128 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
0.4%
61th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

openssl