VID |
22618 |
Severity |
30 |
Port |
80, ... |
Protocol |
TCP |
Class |
WWW |
Detailed Description |
According to its banner, the remote web server is running a version of OpenSSL 1.0.0 prior to 1.0.0m. The OpenSSL library is, therefore, reportedly affected by the following vulnerability :
- An error exists related to the implementation of the Elliptic Curve Digital Signature Algorithm (ECDSA) that could allow nonce disclosure via the 'FLUSH+RELOAD' cache side-channel attack. (CVE-2014-0076)
* References: http://eprint.iacr.org/2014/140 http://www.openssl.org/news/vulnerabilities.html#2014-0076
* Platforms Affected: OpenSSL 1.0.0 prior to 1.0.0m Linux Any version Unix Any version Microsoft Windows Any version |
Recommendation |
Upgrade to the latest version of OpenSSL (1.0.0m or later), available from the OpenSSL Web site at http://www.openssl.org/ |
Related URL |
CVE-2014-0076 (CVE) |
Related URL |
66363 (SecurityFocus) |
Related URL |
(ISS) |
|