CVE Vulnerabilities

CVE-2003-0131

Published: Mar 24, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the Klima-Pokorny-Rosa attack.

Affected Software

NameVendorStart VersionEnd Version
OpensslOpenssl0.9.6 (including)0.9.6 (including)
OpensslOpenssl0.9.6a (including)0.9.6a (including)
OpensslOpenssl0.9.6b (including)0.9.6b (including)
OpensslOpenssl0.9.6c (including)0.9.6c (including)
OpensslOpenssl0.9.6d (including)0.9.6d (including)
OpensslOpenssl0.9.6e (including)0.9.6e (including)
OpensslOpenssl0.9.6g (including)0.9.6g (including)
OpensslOpenssl0.9.6h (including)0.9.6h (including)
OpensslOpenssl0.9.6i (including)0.9.6i (including)
OpensslOpenssl0.9.7 (including)0.9.7 (including)
OpensslOpenssl0.9.7a (including)0.9.7a (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Enterprise Linux ES version 2.1RedHat*
Red Hat Enterprise Linux WS version 2.1RedHat*
Red Hat Linux 6.2RedHat*
Red Hat Linux 7.0RedHat*
Red Hat Linux 7.1RedHat*
Red Hat Linux 7.1RedHat*
Red Hat Linux 7.2RedHat*
Red Hat Linux 7.3RedHat*
Red Hat Linux 8.0RedHat*
Red Hat Linux 9RedHat*
Red Hat Linux Advanced Workstation 2.1RedHat*
Red Hat Stronghold 3RedHat*
Red Hat Stronghold 4RedHat*
OpensslUbuntudapper*
OpensslUbuntudevel*
OpensslUbuntuedgy*
OpensslUbuntufeisty*
Openssl097Ubuntudapper*
Openssl097Ubuntudevel*
Openssl097Ubuntuedgy*
Openssl097Ubuntufeisty*

References