← Back

CVE-2003-0147

nvd nist
Published: Mar 31, 2003Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal).

Affected (35)

1 product
Openpkg
1 product
Openssl
1 product
Stunnel
Configuration A
35 vulnerable
Vulnerable SoftwareAffected Versions
Openpkg
All versions
Version 1.1
Version 1.2
Openssl
Version 0.9.6
Version 0.9.6a
Version 0.9.6b
Version 0.9.6c
Version 0.9.6d
Version 0.9.6e
Version 0.9.6g
Version 0.9.6h
Version 0.9.6i
Version 0.9.7
Version 0.9.7a
Stunnel
Version 3.10
Version 3.11
Version 3.12
Version 3.13
Version 3.14
Version 3.15
Version 3.16
Version 3.17
Version 3.18
Version 3.19
Version 3.20
Version 3.21
Version 3.22
Version 3.7
Version 3.8
Version 3.9
Version 4.01
Version 4.02
Version 4.03
Version 4.04
Version 4.0

References (46)

ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txt (unsafe URL)
Source: cve@mitre.org
ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I (unsafe URL)
Source: cve@mitre.org
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txt (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.