5

CVE-2003-0147

OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal).

Data is provided by the National Vulnerability Database (NVD)
OpenpkgOpenpkg Version1.1
OpenpkgOpenpkg Version1.2
OpenSSLOpenSSL Version0.9.6
OpenSSLOpenSSL Version0.9.6a
OpenSSLOpenSSL Version0.9.6b
OpenSSLOpenSSL Version0.9.6c
OpenSSLOpenSSL Version0.9.6d
OpenSSLOpenSSL Version0.9.6e
OpenSSLOpenSSL Version0.9.6g
OpenSSLOpenSSL Version0.9.6h
OpenSSLOpenSSL Version0.9.6i
OpenSSLOpenSSL Version0.9.7
OpenSSLOpenSSL Version0.9.7a
StunnelStunnel Version3.7
StunnelStunnel Version3.8
StunnelStunnel Version3.9
StunnelStunnel Version3.10
StunnelStunnel Version3.11
StunnelStunnel Version3.12
StunnelStunnel Version3.13
StunnelStunnel Version3.14
StunnelStunnel Version3.15
StunnelStunnel Version3.16
StunnelStunnel Version3.17
StunnelStunnel Version3.18
StunnelStunnel Version3.19
StunnelStunnel Version3.20
StunnelStunnel Version3.21
StunnelStunnel Version3.22
StunnelStunnel Version4.0
StunnelStunnel Version4.01
StunnelStunnel Version4.02
StunnelStunnel Version4.03
StunnelStunnel Version4.04
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 20.2% 0.953
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N