CVE Vulnerabilities

CVE-2003-0147

Published: Mar 31, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the servers private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms (Karatsuba and normal).

Affected Software

NameVendorStart VersionEnd Version
OpenpkgOpenpkg**
OpenpkgOpenpkg1.1 (including)1.1 (including)
OpenpkgOpenpkg1.2 (including)1.2 (including)
OpensslOpenssl0.9.6 (including)0.9.6 (including)
OpensslOpenssl0.9.6a (including)0.9.6a (including)
OpensslOpenssl0.9.6b (including)0.9.6b (including)
OpensslOpenssl0.9.6c (including)0.9.6c (including)
OpensslOpenssl0.9.6d (including)0.9.6d (including)
OpensslOpenssl0.9.6e (including)0.9.6e (including)
OpensslOpenssl0.9.6g (including)0.9.6g (including)
OpensslOpenssl0.9.6h (including)0.9.6h (including)
OpensslOpenssl0.9.6i (including)0.9.6i (including)
OpensslOpenssl0.9.7 (including)0.9.7 (including)
OpensslOpenssl0.9.7a (including)0.9.7a (including)
StunnelStunnel3.7 (including)3.7 (including)
StunnelStunnel3.8 (including)3.8 (including)
StunnelStunnel3.9 (including)3.9 (including)
StunnelStunnel3.10 (including)3.10 (including)
StunnelStunnel3.11 (including)3.11 (including)
StunnelStunnel3.12 (including)3.12 (including)
StunnelStunnel3.13 (including)3.13 (including)
StunnelStunnel3.14 (including)3.14 (including)
StunnelStunnel3.15 (including)3.15 (including)
StunnelStunnel3.16 (including)3.16 (including)
StunnelStunnel3.17 (including)3.17 (including)
StunnelStunnel3.18 (including)3.18 (including)
StunnelStunnel3.19 (including)3.19 (including)
StunnelStunnel3.20 (including)3.20 (including)
StunnelStunnel3.21 (including)3.21 (including)
StunnelStunnel3.22 (including)3.22 (including)
StunnelStunnel4.0 (including)4.0 (including)
StunnelStunnel4.01 (including)4.01 (including)
StunnelStunnel4.02 (including)4.02 (including)
StunnelStunnel4.03 (including)4.03 (including)
StunnelStunnel4.04 (including)4.04 (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Enterprise Linux ES version 2.1RedHat*
Red Hat Enterprise Linux WS version 2.1RedHat*
Red Hat Linux 6.2RedHat*
Red Hat Linux 7.0RedHat*
Red Hat Linux 7.1RedHat*
Red Hat Linux 7.1RedHat*
Red Hat Linux 7.2RedHat*
Red Hat Linux 7.3RedHat*
Red Hat Linux 8.0RedHat*
Red Hat Linux 9RedHat*
Red Hat Linux Advanced Workstation 2.1RedHat*
Red Hat Stronghold 3RedHat*
Red Hat Stronghold 4RedHat*
OpensslUbuntudapper*
OpensslUbuntudevel*
OpensslUbuntuedgy*
OpensslUbuntufeisty*
Openssl097Ubuntudapper*
Openssl097Ubuntudevel*
Openssl097Ubuntuedgy*
Openssl097Ubuntufeisty*

References