CVE-2003-0147

Description

OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the servers private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms (Karatsuba and normal).

Risk Information

Base Score
5.1
MODERATE
Vector
AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
26.684

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2003-0131,CVE-2003-0147 are fixed in OpenSSL (x64) 0.9.6jWindows
Vulnerabilities CVE-2003-0131,CVE-2003-0147 are fixed in OpenSSL (x64) 0.9.7bWindows
Multiple Vulnerabilities are affected in stunnel 3.7Windows
Multiple Vulnerabilities are affected in stunnel 3.8Windows
Multiple Vulnerabilities are affected in stunnel 3.10Windows
Multiple Vulnerabilities are affected in stunnel 3.11Windows
Multiple Vulnerabilities are affected in stunnel 3.12Windows
Multiple Vulnerabilities are affected in stunnel 3.13Windows
Multiple Vulnerabilities are affected in stunnel 3.14Windows
Multiple Vulnerabilities are affected in stunnel 3.15Windows
Multiple Vulnerabilities are affected in stunnel 3.16Windows
Multiple Vulnerabilities are affected in stunnel 3.17Windows
Multiple Vulnerabilities are affected in stunnel 3.18Windows
Multiple Vulnerabilities are affected in stunnel 3.19Windows
Multiple Vulnerabilities are affected in stunnel 3.20Windows
Multiple Vulnerabilities are affected in stunnel 3.21Windows
Multiple Vulnerabilities are affected in stunnel 3.22Windows
Multiple Vulnerabilities are affected in stunnel 3.9Windows
Multiple Vulnerabilities are affected in stunnel 4.04Windows
Vulnerabilities CVE-2003-0147,CVE-2003-0740,CVE-2008-2400,CVE-2014-0016 are affected in stunnel 4.0Windows
Vulnerabilities CVE-2003-0147,CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.01Windows
Vulnerabilities CVE-2003-0147,CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.02Windows
Vulnerabilities CVE-2003-0147,CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.03Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234