The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.
Exploitability
AV:LAC:HAu:NImpact
C:PI:NA:N1.2/AV:L/AC:H/Au:N/C:P/I:N/A:N