CVE-2003-0078

Impact:
Moderate
Public Date:
2003-02-19
Bugzilla:
1616956: CVE-2003-0078 security flaw

The MITRE CVE dictionary describes this issue as:

ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack."

Find out more about CVE-2003-0078 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 2.1 RHSA-2003:063 2003-03-10
Red Hat Linux 7.2 RHSA-2003:062 2003-03-06
Red Hat Linux 6.2 RHSA-2003:062 2003-03-06
Red Hat Stronghold 3 RHSA-2003:104 2003-03-18
Red Hat Linux 7.1 RHSA-2003:205 2003-06-23
Red Hat Linux 7.1 RHSA-2003:062 2003-03-06
Red Hat Stronghold 4 RHSA-2003:082 2003-03-03
Red Hat Linux 7.3 RHSA-2003:062 2003-03-06
Red Hat Linux 7.0 RHSA-2003:062 2003-03-06
Red Hat Linux 8.0 RHSA-2003:062 2003-03-06

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.