{"api_version":"1","generated_at":"2026-07-23T13:34:04+00:00","cve":"CVE-2003-0078","urls":{"html":"https://cve.report/CVE-2003-0078","api":"https://cve.report/api/cve/CVE-2003-0078.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-0078","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-0078"},"summary":{"title":"CVE-2003-0078","description":"ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the \"Vaudenay timing attack.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2003-03-03 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-203","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000570","name":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000570","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Home - Conectiva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:020","name":"http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:020","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Mandrakesoft Security Advisories","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I","name":"ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.ciac.org/ciac/bulletins/n-051.shtml","name":"http://www.ciac.org/ciac/bulletins/n-051.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"N-051: Red Hat Updated OpenSSL Packages Fix Timing Attack","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.linuxsecurity.com/advisories/engarde_advisory-2874.html","name":"http://www.linuxsecurity.com/advisories/engarde_advisory-2874.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"LinuxSecurity.com: EnGarde: OpenSSL timing-based attack vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/3945","name":"http://www.osvdb.org/3945","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.redhat.com/support/errata/RHSA-2003-082.html","name":"http://www.redhat.com/support/errata/RHSA-2003-082.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/6884","name":"http://www.securityfocus.com/bid/6884","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"OpenSSL CBC Error Information Leakage Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.trustix.org/errata/2003/0005","name":"http://www.trustix.org/errata/2003/0005","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"text/plain","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/11369.php","name":"http://www.iss.net/security_center/static/11369.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"ISS X-Force Database:ssl-cbc-information-leak(11369): Multiple SSL/TLS implementation CBC ciphersuites information leak","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2003-205.html","name":"http://www.redhat.com/support/errata/RHSA-2003-205.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2003/dsa-253","name":"http://www.debian.org/security/2003/dsa-253","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Debian -- Security Information -- DSA-253-1 openssl","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2003-104.html","name":"http://www.redhat.com/support/errata/RHSA-2003-104.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=104567627211904&w=2","name":"http://marc.info/?l=bugtraq&m=104567627211904&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-001.txt.asc","name":"ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-001.txt.asc","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=104577183206905&w=2","name":"http://marc.info/?l=bugtraq&m=104577183206905&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"'GLSA:  openssl (200302-10)' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2003-062.html","name":"http://www.redhat.com/support/errata/RHSA-2003-062.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=104568426824439&w=2","name":"http://marc.info/?l=bugtraq&m=104568426824439&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"'[OpenPKG-SA-2003.013] OpenPKG Security Advisory (openssl)' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openssl.org/news/secadv_20030219.txt","name":"http://www.openssl.org/news/secadv_20030219.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch","Vendor Advisory"],"title":"","mime":"text/x-diff","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2003-063.html","name":"http://www.redhat.com/support/errata/RHSA-2003-063.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-0078","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-0078","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"78","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"freebsd","cpe5":"freebsd","cpe6":"4.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"78","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"freebsd","cpe5":"freebsd","cpe6":"4.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"78","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"freebsd","cpe5":"freebsd","cpe6":"4.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"78","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"freebsd","cpe5":"freebsd","cpe6":"4.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"78","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"freebsd","cpe5":"freebsd","cpe6":"4.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"78","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"freebsd","cpe5":"freebsd","cpe6":"4.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"78","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"freebsd","cpe5":"freebsd","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"78","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"openbsd","cpe5":"openbsd","cpe6":"3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"78","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"openbsd","cpe5":"openbsd","cpe6":"3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"78","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openssl","cpe5":"openssl","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"78","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openssl","cpe5":"openssl","cpe6":"0.9.6i","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"78","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openssl","cpe5":"openssl","cpe6":"0.9.7","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"78","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openssl","cpe5":"openssl","cpe6":"0.9.7","cpe7":"beta1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"78","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openssl","cpe5":"openssl","cpe6":"0.9.7","cpe7":"beta2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"78","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openssl","cpe5":"openssl","cpe6":"0.9.7","cpe7":"beta3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"78","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openssl","cpe5":"openssl","cpe6":"0.9.7","cpe7":"beta4","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"78","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openssl","cpe5":"openssl","cpe6":"0.9.7","cpe7":"beta5","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"78","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openssl","cpe5":"openssl","cpe6":"0.9.7","cpe7":"beta6","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:43:35.347Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20030501-01-I","tags":["vendor-advisory","x_refsource_SGI","x_transferred"],"url":"ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I"},{"name":"3945","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/3945"},{"name":"ssl-cbc-information-leak(11369)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/11369.php"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.openssl.org/news/secadv_20030219.txt"},{"name":"2003-0005","tags":["vendor-advisory","x_refsource_TRUSTIX","x_transferred"],"url":"http://www.trustix.org/errata/2003/0005"},{"name":"DSA-253","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2003/dsa-253"},{"name":"RHSA-2003:205","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2003-205.html"},{"name":"ESA-20030220-005","tags":["vendor-advisory","x_refsource_ENGARDE","x_transferred"],"url":"http://www.linuxsecurity.com/advisories/engarde_advisory-2874.html"},{"name":"N-051","tags":["third-party-advisory","government-resource","x_refsource_CIAC","x_transferred"],"url":"http://www.ciac.org/ciac/bulletins/n-051.shtml"},{"name":"20030219 OpenSSL 0.9.7a and 0.9.6i released","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=104567627211904&w=2"},{"name":"RHSA-2003:104","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2003-104.html"},{"name":"6884","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/6884"},{"name":"NetBSD-SA2003-001","tags":["vendor-advisory","x_refsource_NETBSD","x_transferred"],"url":"ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-001.txt.asc"},{"name":"MDKSA-2003:020","tags":["vendor-advisory","x_refsource_MANDRAKE","x_transferred"],"url":"http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:020"},{"name":"CLSA-2003:570","tags":["vendor-advisory","x_refsource_CONECTIVA","x_transferred"],"url":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000570"},{"name":"20030219 [OpenPKG-SA-2003.013] OpenPKG Security Advisory (openssl)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=104568426824439&w=2"},{"name":"GLSA-200302-10","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=104577183206905&w=2"},{"name":"RHSA-2003:082","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2003-082.html"},{"name":"RHSA-2003:063","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2003-063.html"},{"name":"RHSA-2003:062","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2003-062.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-02-19T00:00:00.000Z","descriptions":[{"lang":"en","value":"ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the \"Vaudenay timing attack.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2010-02-23T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20030501-01-I","tags":["vendor-advisory","x_refsource_SGI"],"url":"ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I"},{"name":"3945","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/3945"},{"name":"ssl-cbc-information-leak(11369)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/11369.php"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.openssl.org/news/secadv_20030219.txt"},{"name":"2003-0005","tags":["vendor-advisory","x_refsource_TRUSTIX"],"url":"http://www.trustix.org/errata/2003/0005"},{"name":"DSA-253","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2003/dsa-253"},{"name":"RHSA-2003:205","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2003-205.html"},{"name":"ESA-20030220-005","tags":["vendor-advisory","x_refsource_ENGARDE"],"url":"http://www.linuxsecurity.com/advisories/engarde_advisory-2874.html"},{"name":"N-051","tags":["third-party-advisory","government-resource","x_refsource_CIAC"],"url":"http://www.ciac.org/ciac/bulletins/n-051.shtml"},{"name":"20030219 OpenSSL 0.9.7a and 0.9.6i released","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=104567627211904&w=2"},{"name":"RHSA-2003:104","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2003-104.html"},{"name":"6884","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/6884"},{"name":"NetBSD-SA2003-001","tags":["vendor-advisory","x_refsource_NETBSD"],"url":"ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-001.txt.asc"},{"name":"MDKSA-2003:020","tags":["vendor-advisory","x_refsource_MANDRAKE"],"url":"http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:020"},{"name":"CLSA-2003:570","tags":["vendor-advisory","x_refsource_CONECTIVA"],"url":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000570"},{"name":"20030219 [OpenPKG-SA-2003.013] OpenPKG Security Advisory (openssl)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=104568426824439&w=2"},{"name":"GLSA-200302-10","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://marc.info/?l=bugtraq&m=104577183206905&w=2"},{"name":"RHSA-2003:082","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2003-082.html"},{"name":"RHSA-2003:063","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2003-063.html"},{"name":"RHSA-2003:062","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2003-062.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-0078","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the \"Vaudenay timing attack.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20030501-01-I","refsource":"SGI","url":"ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I"},{"name":"3945","refsource":"OSVDB","url":"http://www.osvdb.org/3945"},{"name":"ssl-cbc-information-leak(11369)","refsource":"XF","url":"http://www.iss.net/security_center/static/11369.php"},{"name":"http://www.openssl.org/news/secadv_20030219.txt","refsource":"CONFIRM","url":"http://www.openssl.org/news/secadv_20030219.txt"},{"name":"2003-0005","refsource":"TRUSTIX","url":"http://www.trustix.org/errata/2003/0005"},{"name":"DSA-253","refsource":"DEBIAN","url":"http://www.debian.org/security/2003/dsa-253"},{"name":"RHSA-2003:205","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2003-205.html"},{"name":"ESA-20030220-005","refsource":"ENGARDE","url":"http://www.linuxsecurity.com/advisories/engarde_advisory-2874.html"},{"name":"N-051","refsource":"CIAC","url":"http://www.ciac.org/ciac/bulletins/n-051.shtml"},{"name":"20030219 OpenSSL 0.9.7a and 0.9.6i released","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=104567627211904&w=2"},{"name":"RHSA-2003:104","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2003-104.html"},{"name":"6884","refsource":"BID","url":"http://www.securityfocus.com/bid/6884"},{"name":"NetBSD-SA2003-001","refsource":"NETBSD","url":"ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-001.txt.asc"},{"name":"MDKSA-2003:020","refsource":"MANDRAKE","url":"http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:020"},{"name":"CLSA-2003:570","refsource":"CONECTIVA","url":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000570"},{"name":"20030219 [OpenPKG-SA-2003.013] OpenPKG Security Advisory (openssl)","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=104568426824439&w=2"},{"name":"GLSA-200302-10","refsource":"GENTOO","url":"http://marc.info/?l=bugtraq&m=104577183206905&w=2"},{"name":"RHSA-2003:082","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2003-082.html"},{"name":"RHSA-2003:063","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2003-063.html"},{"name":"RHSA-2003:062","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2003-062.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-0078","datePublished":"2004-09-01T04:00:00.000Z","dateReserved":"2003-02-10T00:00:00.000Z","dateUpdated":"2024-08-08T01:43:35.347Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-03-03 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-203","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*","versionEndExcluding":"0.9.6i","matchCriteriaId":"7693CC10-F1E9-47D4-81C0-EF0E3D9CAE10"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:0.9.6i:*:*:*:*:*:*:*","matchCriteriaId":"5B76FE2D-FBE0-4A3B-A0EA-179332D74F0E"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:0.9.7:-:*:*:*:*:*:*","matchCriteriaId":"CC626D0B-6D4F-4727-8933-B9EE7546ABA5"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:0.9.7:beta1:*:*:*:*:*:*","matchCriteriaId":"9E3AB748-E463-445C-ABAB-4FEDDFD1878B"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:0.9.7:beta2:*:*:*:*:*:*","matchCriteriaId":"660E4B8D-AABA-4520-BC4D-CF8E76E07C05"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:0.9.7:beta3:*:*:*:*:*:*","matchCriteriaId":"85BFEED5-4941-41BB-93D1-CD5C2A41290E"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:0.9.7:beta4:*:*:*:*:*:*","matchCriteriaId":"9644CC68-1E91-45E7-8C53-1E3FC9976A4E"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:0.9.7:beta5:*:*:*:*:*:*","matchCriteriaId":"9B1B98C4-1FFD-4A7C-AA86-A34BC6F7AB31"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:0.9.7:beta6:*:*:*:*:*:*","matchCriteriaId":"73934717-2DA3-4614-A076-D6EDA5EB0626"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:4.2:*:*:*:*:*:*:*","matchCriteriaId":"DF49BF03-C25E-4737-84D5-892895C86C58"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:4.3:*:*:*:*:*:*:*","matchCriteriaId":"D2019E0E-426B-43AF-8904-1B811AE171E8"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:4.4:*:*:*:*:*:*:*","matchCriteriaId":"55C5FC1A-1253-4390-A4FC-573BB14EA937"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:4.5:*:*:*:*:*:*:*","matchCriteriaId":"44308D13-D935-4FF8-AB52-F0E115ED1AD2"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:4.6:*:*:*:*:*:*:*","matchCriteriaId":"9C001822-FDF8-497C-AC2C-B59A00E9ACD2"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:4.7:*:*:*:*:*:*:*","matchCriteriaId":"B86C77AB-B8FF-4376-9B4E-C88417396F3D"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:5.0:*:*:*:*:*:*:*","matchCriteriaId":"61EBA52A-2D8B-4FB5-866E-AE67CE1842E7"},{"vulnerable":true,"criteria":"cpe:2.3:o:openbsd:openbsd:3.1:*:*:*:*:*:*:*","matchCriteriaId":"DA33E7E2-DE7B-411E-8991-718DA0988C51"},{"vulnerable":true,"criteria":"cpe:2.3:o:openbsd:openbsd:3.2:*:*:*:*:*:*:*","matchCriteriaId":"1957B3C0-7F25-469B-BC3F-7B09260837ED"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"78","Ordinal":"1","Title":"CVE-2003-0078","CVE":"CVE-2003-0078","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"78","Ordinal":"1","NoteData":"ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the \"Vaudenay timing attack.\"","Type":"Description","Title":"CVE-2003-0078"},{"CveYear":"2003","CveId":"78","Ordinal":"2","NoteData":"2004-09-01","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"78","Ordinal":"3","NoteData":"2010-02-22","Type":"Other","Title":"Modified"}]}}}