2017-10-16 12:31:07 -04:00
{
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org" ,
"ID" : "CVE-2003-0147" ,
"STATE" : "PUBLIC"
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "n/a" ,
"version" : {
"version_data" : [
{
"version_value" : "n/a"
}
]
}
}
]
} ,
"vendor_name" : "n/a"
}
]
}
} ,
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
"value" : "OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms (\"Karatsuba\" and normal)."
}
]
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "n/a"
}
]
}
]
} ,
"references" : {
"reference_data" : [
{
2018-04-05 09:33:01 -04:00
"name" : "20030313 Vulnerability in OpenSSL" ,
"refsource" : "BUGTRAQ" ,
2017-10-16 12:31:07 -04:00
"url" : "http://marc.info/?l=bugtraq&m=104766550528628&w=2"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL" ,
"refsource" : "BUGTRAQ" ,
2018-10-19 11:05:17 -04:00
"url" : "http://www.securityfocus.com/archive/1/316165/30/25370/threaded"
2017-10-16 12:31:07 -04:00
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "20030327 Immunix Secured OS 7+ openssl update" ,
"refsource" : "BUGTRAQ" ,
2018-10-19 11:05:17 -04:00
"url" : "http://www.securityfocus.com/archive/1/316577/30/25310/threaded"
2017-10-16 12:31:07 -04:00
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "20030313 OpenSSL Private Key Disclosure" ,
"refsource" : "VULNWATCH" ,
2017-10-16 12:31:07 -04:00
"url" : "http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0130.html"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "http://www.openssl.org/news/secadv_20030317.txt" ,
"refsource" : "CONFIRM" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.openssl.org/news/secadv_20030317.txt"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "20030317 [ADVISORY] Timing Attack on OpenSSL" ,
"refsource" : "BUGTRAQ" ,
2017-10-16 12:31:07 -04:00
"url" : "http://marc.info/?l=bugtraq&m=104792570615648&w=2"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "http://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf" ,
"refsource" : "MISC" ,
2017-10-16 12:31:07 -04:00
"url" : "http://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "APPLE-SA-2003-03-24" ,
"refsource" : "APPLE" ,
2018-10-19 11:05:17 -04:00
"url" : "http://www.securityfocus.com/archive/1/316165/30/25370/threaded"
2017-10-16 12:31:07 -04:00
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "CSSA-2003-014.0" ,
"refsource" : "CALDERA" ,
2017-10-16 12:31:07 -04:00
"url" : "ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txt"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "CLA-2003:625" ,
"refsource" : "CONECTIVA" ,
2017-10-16 12:31:07 -04:00
"url" : "http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000625"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "DSA-288" ,
"refsource" : "DEBIAN" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.debian.org/security/2003/dsa-288"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "GLSA-200303-24" ,
"refsource" : "GENTOO" ,
2017-10-16 12:31:07 -04:00
"url" : "http://marc.info/?l=bugtraq&m=104861762028637&w=2"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "GLSA-200303-15" ,
"refsource" : "GENTOO" ,
2017-10-16 12:31:07 -04:00
"url" : "http://marc.info/?l=bugtraq&m=104829040921835&w=2"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "GLSA-200303-23" ,
"refsource" : "GENTOO" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.gentoo.org/security/en/glsa/glsa-200303-23.xml"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "IMNX-2003-7+-001-01" ,
"refsource" : "IMMUNIX" ,
2018-10-19 11:05:17 -04:00
"url" : "http://www.securityfocus.com/archive/1/316577/30/25310/threaded"
2017-10-16 12:31:07 -04:00
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "MDKSA-2003:035" ,
"refsource" : "MANDRAKE" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:035"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "OpenPKG-SA-2003.019" ,
"refsource" : "OPENPKG" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.019.html"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "RHSA-2003:101" ,
"refsource" : "REDHAT" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.redhat.com/support/errata/RHSA-2003-101.html"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "RHSA-2003:102" ,
"refsource" : "REDHAT" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.redhat.com/support/errata/RHSA-2003-102.html"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "20030501-01-I" ,
"refsource" : "SGI" ,
2017-10-16 12:31:07 -04:00
"url" : "ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "20030320 [OpenPKG-SA-2003.026] OpenPKG Security Advisory (openssl)" ,
"refsource" : "BUGTRAQ" ,
2017-10-16 12:31:07 -04:00
"url" : "http://marc.info/?l=bugtraq&m=104819602408063&w=2"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "VU#997481" ,
"refsource" : "CERT-VN" ,
2017-10-16 12:31:07 -04:00
"url" : "http://www.kb.cert.org/vuls/id/997481"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "oval:org.mitre.oval:def:466" ,
"refsource" : "OVAL" ,
2017-10-16 12:31:07 -04:00
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A466"
}
]
}
}