CVE-2003-0147

Scores

EPSS

0.287low28.7%
0%20%40%60%80%100%

Percentile: 28.7%

CVSS

5.0medium2.0
0246810

CVSS Score: 5.0/10

All CVSS Scores

CVSS 2.0
5.0

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Description

OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server’s private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms (“Karatsuba” and normal).

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debiannvd

Exploits

Exploit ID: 146

Source: exploitdb

URL: https://www.exploit-db.com/exploits/146

Exploit ID: 22264

Source: exploitdb

URL: https://www.exploit-db.com/exploits/22264

Exploit ID: 23199

Source: exploitdb

URL: https://www.exploit-db.com/exploits/23199

Exploit ID: 40347

Source: exploitdb

URL: https://www.exploit-db.com/exploits/40347

Vulnerable Software (5)

Type: Configuration

Product: openssl

Operating System: debian

Trait:
{  "fixed": "0.9.7b-1"}

Source: debian

Type: Configuration

Product: openssl096

Operating System: debian

Trait:
{  "fixed": "0.9.6j-1"}

Source: debian

Type: Configuration

Vendor: *

Product: openpkg

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:openpkg:openpkg:*:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:openpkg:openpkg:1.1:*:*:*:*:*:*:*",      "vu...

Source: nvd

Type: Configuration

Vendor: *

Product: openssl

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:openpkg:openpkg:*:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:openpkg:openpkg:1.1:*:*:*:*:*:*:*",      "vu...

Source: nvd

Type: Configuration

Vendor: *

Product: stunnel

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:openpkg:openpkg:*:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:openpkg:openpkg:1.1:*:*:*:*:*:*:*",      "vu...

Source: nvd

End of list