CVE-2003-0078
ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack."
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 13.72% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- openssl/openssl · freebsd/freebsd · openbsd/openbsd
- Source
- cve@mitre.org
References
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-001.txt.ascBroken Link
- ftp://patches.sgi.com/support/free/security/advisories/20030501-01-IBroken Link
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000570Broken Link
- http://marc.info/?l=bugtraq&m=104567627211904&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=104568426824439&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=104577183206905&w=2Third Party Advisory
- http://www.ciac.org/ciac/bulletins/n-051.shtmlBroken Link
- http://www.debian.org/security/2003/dsa-253Broken Link, Vendor Advisory
- http://www.iss.net/security_center/static/11369.phpBroken Link, Vendor Advisory
- http://www.linuxsecurity.com/advisories/engarde_advisory-2874.htmlBroken Link
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:020Broken Link
- http://www.openssl.org/news/secadv_20030219.txtBroken Link, Patch, Vendor Advisory
- http://www.osvdb.org/3945Broken Link
- http://www.redhat.com/support/errata/RHSA-2003-062.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2003-063.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2003-082.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2003-104.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2003-205.htmlBroken Link
- http://www.securityfocus.com/bid/6884Broken Link, Third Party Advisory, VDB Entry
- http://www.trustix.org/errata/2003/0005Broken Link
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-001.txt.ascBroken Link
- ftp://patches.sgi.com/support/free/security/advisories/20030501-01-IBroken Link
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000570Broken Link
- http://marc.info/?l=bugtraq&m=104567627211904&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=104568426824439&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=104577183206905&w=2Third Party Advisory
- http://www.ciac.org/ciac/bulletins/n-051.shtmlBroken Link
- http://www.debian.org/security/2003/dsa-253Broken Link, Vendor Advisory
- http://www.iss.net/security_center/static/11369.phpBroken Link, Vendor Advisory
- http://www.linuxsecurity.com/advisories/engarde_advisory-2874.htmlBroken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.