CVE-2014-0076: OpenSSL

Low severity, CVSS 1.9. EPSS: 0.8% chance of exploitation in the next 30 days.

The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local users to obtain ECDSA nonces via a FLUSH+RELOAD cache side-channel attack.

Affected products

  • OpenSSL OpenSSL: up to and including 1.0.0l; version 0.9.1c only; version 0.9.2b only; version 0.9.3 only; version 0.9.3a only; version 0.9.4 only; …

Published 2014-03-25. Last modified 2026-06-17.