Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0076

Опубликовано: 25 мар. 2014
Источник: ubuntu
Приоритет: medium
CVSS2: 1.9

Описание

The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local users to obtain ECDSA nonces via a FLUSH+RELOAD cache side-channel attack.

РелизСтатусПримечание
devel

released

1.0.1f-1ubuntu2
lucid

not-affected

code not present
precise

released

1.0.1-4ubuntu5.12
quantal

released

1.0.1c-3ubuntu2.7
saucy

released

1.0.1e-3ubuntu1.2
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

code not present
lucid

DNE

precise

not-affected

code not present
quantal

not-affected

code not present
saucy

not-affected

code not present
upstream

needs-triage

Показывать по

1.9 Low

CVSS2

Связанные уязвимости

redhat
больше 11 лет назад

The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local users to obtain ECDSA nonces via a FLUSH+RELOAD cache side-channel attack.

nvd
больше 11 лет назад

The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local users to obtain ECDSA nonces via a FLUSH+RELOAD cache side-channel attack.

debian
больше 11 лет назад

The Montgomery ladder implementation in OpenSSL through 1.0.0l does no ...

github
около 3 лет назад

The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local users to obtain ECDSA nonces via a FLUSH+RELOAD cache side-channel attack.

fstec
больше 11 лет назад

Уязвимость программного обеспечения Cisco Unified Communications Manager, позволяющая злоумышленнику получить одноразовый код (nonce) ECDSA

1.9 Low

CVSS2