VDB
DEBIAN-CVE-2014-0076
DEBIAN-CVE-2014-0076
PUBLISHED
The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local users to obtain ECDSA nonces via a FLUSH+RELOAD cache side-channel attack.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:13 | openssl | 0, 0, 0 |
| Debian:14 | openssl | 0, 0, 0 |
| Debian:11 | openssl | 0, 0, 0 |
| Debian:12 | openssl | 0, 0, 0 |
Timeline
- Mar 25, 2014 CVE Published
- Apr 28, 2026 CVE Updated