CVE-2003-0147

Impact:
Important
Public Date:
2003-03-14
Bugzilla:
1616986: CVE-2003-0147 security flaw

The MITRE CVE dictionary describes this issue as:

OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal).

Find out more about CVE-2003-0147 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Linux 7.0 RHSA-2003:101 2003-04-01
Red Hat Linux 6.2 RHSA-2003:101 2003-04-01
Red Hat Stronghold 3 RHSA-2003:117 2003-04-15
Red Hat Stronghold 4 RHSA-2003:116 2003-03-28
Red Hat Linux 7.1 RHSA-2003:205 2003-06-23
Red Hat Linux 7.2 RHSA-2003:101 2003-04-01
Red Hat Linux 7.3 RHSA-2003:101 2003-04-01
Red Hat Enterprise Linux 2.1 RHSA-2003:102 2003-03-31
Red Hat Linux 8.0 RHSA-2003:101 2003-04-01
Red Hat Linux 7.1 RHSA-2003:101 2003-04-01
Red Hat Linux 9 RHSA-2003:101 2003-04-01

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.