CVE-2003-0078

ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack."
References
Link Resource
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-001.txt.asc Broken Link
ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I Broken Link
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000570 Broken Link
http://marc.info/?l=bugtraq&m=104567627211904&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=104568426824439&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=104577183206905&w=2 Third Party Advisory
http://www.ciac.org/ciac/bulletins/n-051.shtml Broken Link
http://www.debian.org/security/2003/dsa-253 Broken Link Vendor Advisory
http://www.iss.net/security_center/static/11369.php Broken Link Vendor Advisory
http://www.linuxsecurity.com/advisories/engarde_advisory-2874.html Broken Link
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:020 Broken Link
http://www.openssl.org/news/secadv_20030219.txt Broken Link Patch Vendor Advisory
http://www.osvdb.org/3945 Broken Link
http://www.redhat.com/support/errata/RHSA-2003-062.html Broken Link
http://www.redhat.com/support/errata/RHSA-2003-063.html Broken Link
http://www.redhat.com/support/errata/RHSA-2003-082.html Broken Link
http://www.redhat.com/support/errata/RHSA-2003-104.html Broken Link
http://www.redhat.com/support/errata/RHSA-2003-205.html Broken Link
http://www.securityfocus.com/bid/6884 Broken Link Third Party Advisory VDB Entry
http://www.trustix.org/errata/2003/0005 Broken Link
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-001.txt.asc Broken Link
ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I Broken Link
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000570 Broken Link
http://marc.info/?l=bugtraq&m=104567627211904&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=104568426824439&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=104577183206905&w=2 Third Party Advisory
http://www.ciac.org/ciac/bulletins/n-051.shtml Broken Link
http://www.debian.org/security/2003/dsa-253 Broken Link Vendor Advisory
http://www.iss.net/security_center/static/11369.php Broken Link Vendor Advisory
http://www.linuxsecurity.com/advisories/engarde_advisory-2874.html Broken Link
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:020 Broken Link
http://www.openssl.org/news/secadv_20030219.txt Broken Link Patch Vendor Advisory
http://www.osvdb.org/3945 Broken Link
http://www.redhat.com/support/errata/RHSA-2003-062.html Broken Link
http://www.redhat.com/support/errata/RHSA-2003-063.html Broken Link
http://www.redhat.com/support/errata/RHSA-2003-082.html Broken Link
http://www.redhat.com/support/errata/RHSA-2003-104.html Broken Link
http://www.redhat.com/support/errata/RHSA-2003-205.html Broken Link
http://www.securityfocus.com/bid/6884 Broken Link Third Party Advisory VDB Entry
http://www.trustix.org/errata/2003/0005 Broken Link
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:0.9.6i:*:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:0.9.7:-:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:0.9.7:beta1:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:0.9.7:beta2:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:0.9.7:beta3:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:0.9.7:beta4:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:0.9.7:beta5:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:0.9.7:beta6:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:freebsd:freebsd:4.2:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:4.3:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:4.4:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:4.5:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:4.6:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:4.7:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:5.0:*:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:3.1:*:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:3.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2003-03-03 05:00

Updated : 2025-04-03 01:03


NVD link : CVE-2003-0078

Mitre link : CVE-2003-0078

CVE.ORG link : CVE-2003-0078


JSON object : View

Products Affected

openssl

  • openssl

openbsd

  • openbsd

freebsd

  • freebsd
CWE
CWE-203

Observable Discrepancy