CVE Vulnerabilities

CVE-2003-0147

Published: Mar 31, 2003 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the servers private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms (Karatsuba and normal).

Affected Software

Name Vendor Start Version End Version
Openpkg Openpkg * *
Openpkg Openpkg 1.1 (including) 1.1 (including)
Openpkg Openpkg 1.2 (including) 1.2 (including)
Openssl Openssl 0.9.6 (including) 0.9.6 (including)
Openssl Openssl 0.9.6a (including) 0.9.6a (including)
Openssl Openssl 0.9.6b (including) 0.9.6b (including)
Openssl Openssl 0.9.6c (including) 0.9.6c (including)
Openssl Openssl 0.9.6d (including) 0.9.6d (including)
Openssl Openssl 0.9.6e (including) 0.9.6e (including)
Openssl Openssl 0.9.6g (including) 0.9.6g (including)
Openssl Openssl 0.9.6h (including) 0.9.6h (including)
Openssl Openssl 0.9.6i (including) 0.9.6i (including)
Openssl Openssl 0.9.7 (including) 0.9.7 (including)
Openssl Openssl 0.9.7a (including) 0.9.7a (including)
Stunnel Stunnel 3.7 (including) 3.7 (including)
Stunnel Stunnel 3.8 (including) 3.8 (including)
Stunnel Stunnel 3.9 (including) 3.9 (including)
Stunnel Stunnel 3.10 (including) 3.10 (including)
Stunnel Stunnel 3.11 (including) 3.11 (including)
Stunnel Stunnel 3.12 (including) 3.12 (including)
Stunnel Stunnel 3.13 (including) 3.13 (including)
Stunnel Stunnel 3.14 (including) 3.14 (including)
Stunnel Stunnel 3.15 (including) 3.15 (including)
Stunnel Stunnel 3.16 (including) 3.16 (including)
Stunnel Stunnel 3.17 (including) 3.17 (including)
Stunnel Stunnel 3.18 (including) 3.18 (including)
Stunnel Stunnel 3.19 (including) 3.19 (including)
Stunnel Stunnel 3.20 (including) 3.20 (including)
Stunnel Stunnel 3.21 (including) 3.21 (including)
Stunnel Stunnel 3.22 (including) 3.22 (including)
Stunnel Stunnel 4.0 (including) 4.0 (including)
Stunnel Stunnel 4.01 (including) 4.01 (including)
Stunnel Stunnel 4.02 (including) 4.02 (including)
Stunnel Stunnel 4.03 (including) 4.03 (including)
Stunnel Stunnel 4.04 (including) 4.04 (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 RedHat *
Red Hat Enterprise Linux ES version 2.1 RedHat *
Red Hat Enterprise Linux WS version 2.1 RedHat *
Red Hat Linux 6.2 RedHat *
Red Hat Linux 7.0 RedHat *
Red Hat Linux 7.1 RedHat *
Red Hat Linux 7.1 RedHat *
Red Hat Linux 7.2 RedHat *
Red Hat Linux 7.3 RedHat *
Red Hat Linux 8.0 RedHat *
Red Hat Linux 9 RedHat *
Red Hat Linux Advanced Workstation 2.1 RedHat *
Red Hat Stronghold 3 RedHat *
Red Hat Stronghold 4 RedHat *
Openssl Ubuntu dapper *
Openssl Ubuntu devel *
Openssl Ubuntu edgy *
Openssl Ubuntu feisty *
Openssl097 Ubuntu dapper *
Openssl097 Ubuntu devel *
Openssl097 Ubuntu edgy *
Openssl097 Ubuntu feisty *

References