CVE-2014-0076

Description

The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local users to obtain ECDSA nonces via a FLUSH+RELOAD cache side-channel attack.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.396

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2014-0160,CVE-2014-0076 are fixed in OpenSSL (x64) 1.0.1gWindows
Multiple vulnerabilities fixed in OpenSSL (x64) 0.9.8zaWindows
Multiple vulnerabilities fixed in OpenSSL (x64) 1.0.0mWindows
Vulnerabilities CVE-2014-0076,CVE-2014-0963 are affected in IBM Tivoli Monitoring 6.22Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.23Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.30Windows
Multiple vulnerabilities are fixed in OS X Mavericks 10.9.5 UpdateMac
Multiple vulnerabilities are fixed in OS X Mavericks 10.9.5 Update (Combo)Mac
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products For Cisco IOSNCM
CVE-2014-0076NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706090Security Update for Cisco IOS Amsterdam-17.2.1r
PATCH-600222OS X Mavericks 10.9.5 Update
PATCH-600223OS X Mavericks 10.9.5 Update (Combo)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234