CVE-2003-0078
Last modified
CVE-2003-0078 is a vulnerability of currently unknown severity. ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack.". EPSS estimates a 13.72% chance of exploitation in the next 30 days.
Description
ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openssl | Openssl | < 0.9.6i |
| Openssl | Openssl | 0.9.6i |
| Openssl | Openssl | 0.9.7 |
| Freebsd | Freebsd | 4.2 |
| Freebsd | Freebsd | 4.3 |
| Freebsd | Freebsd | 4.4 |
| Freebsd | Freebsd | 4.5 |
| Freebsd | Freebsd | 4.6 |
| Freebsd | Freebsd | 4.7 |
| Freebsd | Freebsd | 5.0 |
| Openbsd | Openbsd | 3.1 |
| Openbsd | Openbsd | 3.2 |
References
- http://marc.info/?l=bugtraq&m=104567627211904&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=104568426824439&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=104577183206905&w=2Third Party Advisory
- http://www.debian.org/security/2003/dsa-253Broken Link, Vendor Advisory
- http://www.iss.net/security_center/static/11369.phpBroken Link, Vendor Advisory
- http://www.openssl.org/news/secadv_20030219.txtBroken Link, Patch, Vendor Advisory
- http://www.osvdb.org/3945Broken Link
- http://www.securityfocus.com/bid/6884Broken Link, Third Party Advisory, VDB Entry
- http://www.trustix.org/errata/2003/0005Broken Link
- http://marc.info/?l=bugtraq&m=104567627211904&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=104568426824439&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=104577183206905&w=2Third Party Advisory
- http://www.debian.org/security/2003/dsa-253Broken Link, Vendor Advisory
- http://www.iss.net/security_center/static/11369.phpBroken Link, Vendor Advisory
- http://www.openssl.org/news/secadv_20030219.txtBroken Link, Patch, Vendor Advisory
- http://www.osvdb.org/3945Broken Link
- http://www.securityfocus.com/bid/6884Broken Link, Third Party Advisory, VDB Entry
- http://www.trustix.org/errata/2003/0005Broken Link
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-0078?
How severe is CVE-2003-0078?
How do I fix CVE-2003-0078?
Are you affected by CVE-2003-0078?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
