VDB

CVE-2003-0078

CVE-2003-0078 PUBLISHED CVSS 5 MEDIUM

ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack."

EPSS 13.72% · 96.3th percentile

Risk Scores

CVSS 2.0
5
EPSS Score
13.72%
96.3th percentile

Affected Products

VendorProductVersions
openbsdopenbsd3.2, 3.1
n/an/a*
freebsdfreebsd4.3, 4.4, 4.5
opensslopenssl0.9.7, 0.9.7, 0.9.7

Timeline

  • Mar 3, 2003 CVE Published
  • Feb 4, 2022 EPSS Score
  • May 21, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
  • Dec 19, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • Jul 18, 2023 EPSS Score
  • Sep 8, 2023 EPSS Score
  • Dec 23, 2023 EPSS Score
  • Feb 14, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›