CVE-2014-0076
published 2014-03-25CVE-2014-0076: The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it…
PriorityP48low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.94%
57.3th percentile
The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local users to obtain ECDSA nonces via a FLUSH+RELOAD cache side-channel attack.
Affected
80 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | products | — | — |
| debian | openssl | < openssl 1.0.1g-1 (bookworm) | openssl 1.0.1g-1 (bookworm) |
| openssl | openssl | <= 1.0.0l | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv1.9LOW
vendor_cisco10.0CRITICAL
vendor_debian1.9LOW
vendor_redhat1.9LOW
vendor_ubuntu1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple Mac OS X up to 10.9.4 OpenSSL cryptographic issue (HT6443 / Nessus ID 74288)
vuldb·2026-05-08·CVSS 1.9
CVE-2014-0076 [LOW] Apple Mac OS X up to 10.9.4 OpenSSL cryptographic issue (HT6443 / Nessus ID 74288)
A vulnerability was found in Apple Mac OS X up to 10.9.4. It has been declared as critical. This issue affects some unknown processing of the component OpenSSL. Executing a manipulation can lead to cryptographic issues.
The identification of this vulnerability is CVE-2014-0076. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
VulDB
OpenSSL 1.0.1f/1.0.1l ECDSA cryptographic issue (Nessus ID 74288 / ID 175900)
vuldb·2026-05-08·CVSS 1.9
CVE-2014-0076 [LOW] OpenSSL 1.0.1f/1.0.1l ECDSA cryptographic issue (Nessus ID 74288 / ID 175900)
A vulnerability, which was classified as problematic, has been found in OpenSSL 1.0.1f/1.0.1l. This affects an unknown part of the component ECDSA. This manipulation causes cryptographic issues.
This vulnerability is registered as CVE-2014-0076. The attack needs to be launched locally. No exploit is available.
Applying a patch is the recommended action to fix this issue.
GHSA
GHSA-h7hf-9wc6-h849: The Montgomery ladder implementation in OpenSSL through 1
ghsa_unreviewed·2022-05-17
CVE-2014-0076 [LOW] GHSA-h7hf-9wc6-h849: The Montgomery ladder implementation in OpenSSL through 1
The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local users to obtain ECDSA nonces via a FLUSH+RELOAD cache side-channel attack.
OSV
CVE-2014-0076: The Montgomery ladder implementation in OpenSSL through 1
osv·2014-03-25·CVSS 1.9
CVE-2014-0076 [LOW] CVE-2014-0076: The Montgomery ladder implementation in OpenSSL through 1
The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local users to obtain ECDSA nonces via a FLUSH+RELOAD cache side-channel attack.
CISA ICS
Rockwell Automation Stratix 5900
cisa_ics·2017-05-10
Rockwell Automation Stratix 5900
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix 5900
Last RevisedMay 10, 2017
Alert CodeICSA-17-094-04
## CVSS v3 10.0
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Rockwell Automation
Equipment: Stratix 5900
Vulnerabilities: Improper Input Validation, Resource Management Errors, Improper Authentication, Path Traversal.
## REPOSTED INFORMATION
This advisory was originally posted to the NCCIC Portal on April 4, 2017, and is being released to the NCCIC/ICS-CERT web site.
## AFFECTED PRODUCTS
Rockwell Automation reports that these vulnerabilities affect the following Strat
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
vendor_cisco·2014-06-05·CVSS 10.0
CVE-2010-5298 [CRITICAL] Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to execute arbitrary code, create a denial of service (DoS) condition, or perform a man-in-the-middle attack. On June 5, 2014, the OpenSSL Project released a security advisory detailing seven distinct vulnerabilities. The vulnerabilities are referenced in this document as follows:
SSL/TLS Man-in-the-Middle Vulnerability
DTLS Recursion Flaw Vulnerability
DTLS Invalid Fragment Vulnerability
SSL_MODE_RELEASE_BUFFERS NULL Pointer Dereference Vulnerability
SSL_MODE_RELEASE_BUFFERS Session Injection or Denial of Service Vulnerability
Anonymous ECDH Denial of Service Vulnerab
BSD
FreeBSD-SA-14:06.openssl: OpenSSL multiple vulnerabilities
bsd_advisories·2014-04-08·CVSS 1.9
CVE-2014-0076 [LOW] FreeBSD-SA-14:06.openssl: OpenSSL multiple vulnerabilities
FreeBSD-SA-14:06.openssl Security Advisory
The FreeBSD Project
Topic: OpenSSL multiple vulnerabilities
Category: contrib
Module: openssl
Announced: 2014-04-08
Affects: All supported versions of FreeBSD.
Corrected: 2014-04-08 18:27:39 UTC (stable/10, 10.0-STABLE)
2014-04-08 18:27:46 UTC (releng/10.0, 10.0-RELEASE-p1)
2014-04-08 23:16:19 UTC (stable/9, 9.2-STABLE)
2014-04-08 23:16:05 UTC (releng/9.2, 9.2-RELEASE-p4)
2014-04-08 23:16:05 UTC (releng/9.1, 9.1-RELEASE-p11)
2014-04-08 23:16:19 UTC (stable/8, 8.4-STABLE)
2014-04-08 23:16:05 UTC (releng/8.4, 8.4-RELEASE-p8)
2014-04-08 23:16:05 UTC (releng/8.3, 8.3-RELEASE-p15)
CVE Name: CVE-2014-0076, CVE-2014-0160
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and th
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2014-04-07·CVSS 1.9
CVE-2014-0076 [LOW] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: OpenSSL could be made to expose sensitive information over the network,
possibly including private keys.
Neel Mehta discovered that OpenSSL incorrectly handled memory in the TLS
heartbeat extension. An attacker could use this issue to obtain up to 64k
of memory contents from the client or server, possibly leading to the
disclosure of private keys and other sensitive information. (CVE-2014-0160)
Yuval Yarom and Naomi Benger discovered that OpenSSL incorrectly handled
timing during swap operations in the Montgomery ladder implementation. An
attacker could use this issue to perform side-channel attacks and possibly
recover ECDSA nonces. (CVE-2014-0076)
Instructions: After a standard system update you need to reboot your computer to make all
the nece
Red Hat
openssl: ECDSA nonces susceptible to Yarom/Benger flush+reload cache side-channel attack
vendor_redhat·2014-02-14·CVSS 1.9
CVE-2014-0076 [LOW] openssl: ECDSA nonces susceptible to Yarom/Benger flush+reload cache side-channel attack
openssl: ECDSA nonces susceptible to Yarom/Benger flush+reload cache side-channel attack
The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local users to obtain ECDSA nonces via a FLUSH+RELOAD cache side-channel attack.
Statement: Not vulnerable. This issue does not affect the version of openssl and openssl097a as shipped with Red Hat Enterprise Linux 5. This issue does not affect the version of openssl and openssl098e as shipped with Red Hat Enterprise Linux 6 or 7.
Package: openssl (Red Hat Enterprise Linux 5) - Not affected
Package: openssl097a (Red Hat Enterprise Linux 5) - Not affected
Package: openssl (Red Hat Enterprise Linux 6) - Not affected
Package: openssl098e
Debian
CVE-2014-0076: openssl - The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure t...
vendor_debian·2014·CVSS 1.9
CVE-2014-0076 [LOW] CVE-2014-0076: openssl - The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure t...
The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local users to obtain ECDSA nonces via a FLUSH+RELOAD cache side-channel attack.
Scope: local
bookworm: resolved (fixed in 1.0.1g-1)
bullseye: resolved (fixed in 1.0.1g-1)
forky: resolved (fixed in 1.0.1g-1)
sid: resolved (fixed in 1.0.1g-1)
trixie: resolved (fixed in 1.0.1g-1)
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
vendor_cisco
CVE-2014-0076 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
CVE-2014-0076: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to execute arbitrary code, create a denial of service (DoS) condition, or perform a man-in-the-middle attack. On June 5, 2014, the OpenSSL Project released a security advisory detailing seven distinct vulnerabilities. The vulnerabilities are referenced in this document as follows: SSL/TLS Man-in-the-Middle Vulnerability DTLS Recursion Flaw Vulnerability DTLS Invalid Fragment Vulnerability SSL_MODE_RELEASE_BUFFERS NULL Pointer Dereference Vulnerability SSL_MODE_RELEASE_BUFFERS Session Injection or Denial of Service Vulnerability Anonymous ECDH Denial of Ser
No detection rules found.
No public exploits indexed.
arXiv
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
arxiv_fulltext·2025-02-16
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
Yuning Jiang
[email protected]
0000-0003-4791-8452
National University of Singapore
Singapore
Nay Oo
[email protected]
NCS Cyber Special Ops R&D
Singapore
Qiaoran Meng
[email protected]
National University of Singapore
Singapore
Hoon Wei Lim
[email protected]
NCS Cyber Special Ops R&D
Singapore
Biplab Sikdar
[email protected]
National University of Singapore
Singapore
Jiang et al.
## Abstract
As interconnected systems proliferate, safeguarding complex infrastructures against an escalating array of cyber threats has become an urgent challenge. The growing number of vulnerabilities, coupled with resource constraints, makes addressing every vulnerability impractical, thereby rende
arXiv
Cache Refinement Type for Side-Channel Detection of Cryptographic Software
arxiv_fulltext·2022-10-19
Cache Refinement Type for Side-Channel Detection of Cryptographic Software
Cache Refinement Type for Side-Channel Detection of Cryptographic Software
Ke Jiang
Nanyang Technological University
Singapore
Singapore
[email protected]
Yuyan Bao
University of Waterloo
Waterloo
Ontario
Canada
[email protected]
Shuai Wang
Corresponding authors
Hong Kong University of Science and Technology
Hong Kong
China
[email protected]
Zhibo Liu
Hong Kong University of Science and Technology
Hong Kong
China
[email protected]
Tianwei Zhang
Nanyang Technological University
Singapore
Singapore
[1]
[email protected]
## Abstract
Cache side-channel attacks exhibit severe threats to software security and
privacy, especially for cryptosystems. In this paper, we propose , a novel
refinement type-based tool for detecting cache side channels in crypto software.
Compared
Bugzilla
CVE-2014-0076 openssl: OpenSSL Elliptic Curve Digital Signature Algorithm (ECDSA) nonces susceptible to Yarom/Benger flush+reload cache side-channel attack [fedora-all]
bugzilla·2014-03-25·CVSS 1.9
CVE-2014-0076 [LOW] CVE-2014-0076 openssl: OpenSSL Elliptic Curve Digital Signature Algorithm (ECDSA) nonces susceptible to Yarom/Benger flush+reload cache side-channel attack [fedora-all]
CVE-2014-0076 openssl: OpenSSL Elliptic Curve Digital Signature Algorithm (ECDSA) nonces susceptible to Yarom/Benger flush+reload cache side-channel attack [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed
Bugzilla
CVE-2014-0076 openssl: ECDSA nonces susceptible to Yarom/Benger flush+reload cache side-channel attack
bugzilla·2014-03-25·CVSS 1.9
CVE-2014-0076 [LOW] CVE-2014-0076 openssl: ECDSA nonces susceptible to Yarom/Benger flush+reload cache side-channel attack
CVE-2014-0076 openssl: ECDSA nonces susceptible to Yarom/Benger flush+reload cache side-channel attack
Yuval Yarom and Naomi Benger report:
"We illustrate a vulnerability introduced to elliptic curve cryptographic protocols when implemented using a function of the OpenSSL cryptographic library. For the given implementation using an elliptic curve E over a binary field with a point G \in E, our attack recovers the majority of the bits of a scalar k when kG is computed using the OpenSSL implementation of the Montgomery ladder. For the Elliptic Curve Digital Signature Algorithm (ECDSA) the scalar k is intended to remain secret. Our attack recovers the scalar k and thus the secret key of the signer and would therefore allow unlimited forgeries. This is possible from snooping on only one sign
http://advisories.mageia.org/MGASA-2014-0165.htmlhttp://eprint.iacr.org/2014/140http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=2198be3483259de374f91e57d247d0fc667aef29http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10629http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00007.htmlhttp://marc.info/?l=bugtraq&m=140266410314613&w=2http://marc.info/?l=bugtraq&m=140317760000786&w=2http://marc.info/?l=bugtraq&m=140389274407904&w=2http://marc.info/?l=bugtraq&m=140389355508263&w=2http://marc.info/?l=bugtraq&m=140448122410568&w=2http://marc.info/?l=bugtraq&m=140482916501310&w=2http://marc.info/?l=bugtraq&m=140621259019789&w=2http://marc.info/?l=bugtraq&m=140752315422991&w=2http://marc.info/?l=bugtraq&m=140904544427729&w=2http://secunia.com/advisories/58492http://secunia.com/advisories/58727http://secunia.com/advisories/58939http://secunia.com/advisories/59040http://secunia.com/advisories/59162http://secunia.com/advisories/59175http://secunia.com/advisories/59264http://secunia.com/advisories/59300http://secunia.com/advisories/59364http://secunia.com/advisories/59374http://secunia.com/advisories/59413http://secunia.com/advisories/59438http://secunia.com/advisories/59445http://secunia.com/advisories/59450http://secunia.com/advisories/59454http://secunia.com/advisories/59490http://secunia.com/advisories/59495http://secunia.com/advisories/59514http://secunia.com/advisories/59655http://secunia.com/advisories/59721http://secunia.com/advisories/60571http://support.apple.com/kb/HT6443http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140605-opensslhttp://www-01.ibm.com/support/docview.wss?uid=isg400001841http://www-01.ibm.com/support/docview.wss?uid=isg400001843http://www-01.ibm.com/support/docview.wss?uid=swg21673137http://www-01.ibm.com/support/docview.wss?uid=swg21676035http://www-01.ibm.com/support/docview.wss?uid=swg21676062http://www-01.ibm.com/support/docview.wss?uid=swg21676092http://www-01.ibm.com/support/docview.wss?uid=swg21676419http://www-01.ibm.com/support/docview.wss?uid=swg21676424http://www-01.ibm.com/support/docview.wss?uid=swg21676501http://www-01.ibm.com/support/docview.wss?uid=swg21676655http://www-01.ibm.com/support/docview.wss?uid=swg21677695http://www-01.ibm.com/support/docview.wss?uid=swg21677828http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-345106.htmhttp://www.mandriva.com/security/advisories?name=MDVSA-2014:067http://www.mandriva.com/security/advisories?name=MDVSA-2015:062http://www.novell.com/support/kb/doc.php?id=7015264http://www.novell.com/support/kb/doc.php?id=7015300http://www.openssl.org/news/secadv_20140605.txthttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.securityfocus.com/bid/66363http://www.ubuntu.com/usn/USN-2165-1https://bugs.gentoo.org/show_bug.cgi?id=505278https://bugzilla.novell.com/show_bug.cgi?id=869945https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05301946https://kc.mcafee.com/corporate/index?page=content&id=SB10075http://advisories.mageia.org/MGASA-2014-0165.htmlhttp://eprint.iacr.org/2014/140http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=2198be3483259de374f91e57d247d0fc667aef29http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10629http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00007.htmlhttp://marc.info/?l=bugtraq&m=140266410314613&w=2http://marc.info/?l=bugtraq&m=140317760000786&w=2http://marc.info/?l=bugtraq&m=140389274407904&w=2http://marc.info/?l=bugtraq&m=140389355508263&w=2http://marc.info/?l=bugtraq&m=140448122410568&w=2http://marc.info/?l=bugtraq&m=140482916501310&w=2http://marc.info/?l=bugtraq&m=140621259019789&w=2http://marc.info/?l=bugtraq&m=140752315422991&w=2http://marc.info/?l=bugtraq&m=140904544427729&w=2http://secunia.com/advisories/58492http://secunia.com/advisories/58727http://secunia.com/advisories/58939http://secunia.com/advisories/59040http://secunia.com/advisories/59162http://secunia.com/advisories/59175http://secunia.com/advisories/59264http://secunia.com/advisories/59300http://secunia.com/advisories/59364http://secunia.com/advisories/59374http://secunia.com/advisories/59413http://secunia.com/advisories/59438http://secunia.com/advisories/59445http://secunia.com/advisories/59450http://secunia.com/advisories/59454http://secunia.com/advisories/59490http://secunia.com/advisories/59495http://secunia.com/advisories/59514http://secunia.com/advisories/59655http://secunia.com/advisories/59721http://secunia.com/advisories/60571
+ 28 more references
2014-03-25
Published