CVE-2003-0078
Summary
| CVE | CVE-2003-0078 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-03-03 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Freebsd | Freebsd | 4.2 | All | All | All |
| Operating System | Freebsd | Freebsd | 4.3 | All | All | All |
| Operating System | Freebsd | Freebsd | 4.4 | All | All | All |
| Operating System | Freebsd | Freebsd | 4.5 | All | All | All |
| Operating System | Freebsd | Freebsd | 4.6 | All | All | All |
| Operating System | Freebsd | Freebsd | 4.7 | All | All | All |
| Operating System | Freebsd | Freebsd | 5.0 | All | All | All |
| Operating System | Openbsd | Openbsd | 3.1 | All | All | All |
| Operating System | Openbsd | Openbsd | 3.2 | All | All | All |
| Application | Openssl | Openssl | All | All | All | All |
| Application | Openssl | Openssl | 0.9.6i | All | All | All |
| Application | Openssl | Openssl | 0.9.7 | - | All | All |
| Application | Openssl | Openssl | 0.9.7 | beta1 | All | All |
| Application | Openssl | Openssl | 0.9.7 | beta2 | All | All |
| Application | Openssl | Openssl | 0.9.7 | beta3 | All | All |
| Application | Openssl | Openssl | 0.9.7 | beta4 | All | All |
| Application | Openssl | Openssl | 0.9.7 | beta5 | All | All |
| Application | Openssl | Openssl | 0.9.7 | beta6 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Home - Conectiva | af854a3a-2127-422b-91ae-364da2661108 | distro.conectiva.com.br | Broken Link |
| Mandrakesoft Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | www.mandrakesoft.com | Broken Link |
| patches.sgi.com/support/free/security/advisories/20030501-01-I | af854a3a-2127-422b-91ae-364da2661108 | patches.sgi.com | Broken Link |
| N-051: Red Hat Updated OpenSSL Packages Fix Timing Attack | af854a3a-2127-422b-91ae-364da2661108 | www.ciac.org | Broken Link |
| LinuxSecurity.com: EnGarde: OpenSSL timing-based attack vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.linuxsecurity.com | Broken Link |
| www.osvdb.org/3945 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Broken Link |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link |
| OpenSSL CBC Error Information Leakage Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| www.trustix.org/errata/2003/0005 | af854a3a-2127-422b-91ae-364da2661108 | www.trustix.org | Broken Link |
| ISS X-Force Database:ssl-cbc-information-leak(11369): Multiple SSL/TLS implementation CBC ciphersuites information leak | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Broken Link, Vendor Advisory |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link |
| Debian -- Security Information -- DSA-253-1 openssl | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Broken Link, Vendor Advisory |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link |
| marc.info | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-001.txt.asc | af854a3a-2127-422b-91ae-364da2661108 | ftp.netbsd.org | Broken Link |
| 'GLSA: openssl (200302-10)' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link |
| '[OpenPKG-SA-2003.013] OpenPKG Security Advisory (openssl)' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| www.openssl.org/news/secadv_20030219.txt | af854a3a-2127-422b-91ae-364da2661108 | www.openssl.org | Broken Link, Patch, Vendor Advisory |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.