CVE-2014-0076 (retired)

Priority
Description
The Montgomery ladder implementation in OpenSSL through 1.0.0l does not
ensure that certain swap operations have a constant-time behavior, which
makes it easier for local users to obtain ECDSA nonces via a FLUSH+RELOAD
cache side-channel attack.
Assigned-to
mdeslaur
Notes
Package
Upstream:needs-triage
More Information

Updated: 2019-10-09 07:49:18 UTC (commit 33aea848a182c0afcd0a3f927a01a7ecd9a061ee)