security flaw
Published Sep 1, 2004
5.0
MEDIUMCVSS 2.0
EPSS 13.72%
Description
ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack."
Affected products
No data.
Configuration 1
- < 0.9.6i
- 0.9.6i
- 0.9.7
- 0.9.7
- 0.9.7
- 0.9.7
- 0.9.7
- 0.9.7
- 0.9.7
No data.
Red Hat Enterprise Linux AS (Advanced Server) version 2.1
n/a
Fixed · RHSA-2003:063
Red Hat Enterprise Linux ES version 2.1
n/a
Fixed · RHSA-2003:063
Red Hat Enterprise Linux WS version 2.1
n/a
Fixed · RHSA-2003:063
Red Hat Linux 6.2
n/a
Fixed · RHSA-2003:062
Red Hat Linux 7.0
n/a
Fixed · RHSA-2003:062
Red Hat Linux 7.1
n/a
Fixed · RHSA-2003:062
Red Hat Linux 7.1
n/a
Fixed · RHSA-2003:205
Red Hat Linux 7.2
n/a
Fixed · RHSA-2003:062
Red Hat Linux 7.3
n/a
Fixed · RHSA-2003:062
Red Hat Linux 8.0
n/a
Fixed · RHSA-2003:062
Red Hat Linux Advanced Workstation 2.1
n/a
Fixed · RHSA-2003:063
Red Hat Stronghold 3
n/a
Fixed · RHSA-2003:104
Red Hat Stronghold 4
n/a
Fixed · RHSA-2003:082
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | n/a | Fixed | RHSA-2003:063 |
| Red Hat Enterprise Linux ES version 2.1 | n/a | Fixed | RHSA-2003:063 |
| Red Hat Enterprise Linux WS version 2.1 | n/a | Fixed | RHSA-2003:063 |
| Red Hat Linux 6.2 | n/a | Fixed | RHSA-2003:062 |
| Red Hat Linux 7.0 | n/a | Fixed | RHSA-2003:062 |
| Red Hat Linux 7.1 | n/a | Fixed | RHSA-2003:062 |
| Red Hat Linux 7.1 | n/a | Fixed | RHSA-2003:205 |
| Red Hat Linux 7.2 | n/a | Fixed | RHSA-2003:062 |
| Red Hat Linux 7.3 | n/a | Fixed | RHSA-2003:062 |
| Red Hat Linux 8.0 | n/a | Fixed | RHSA-2003:062 |
| Red Hat Linux Advanced Workstation 2.1 | n/a | Fixed | RHSA-2003:063 |
| Red Hat Stronghold 3 | n/a | Fixed | RHSA-2003:104 |
| Red Hat Stronghold 4 | n/a | Fixed | RHSA-2003:082 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (21 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 13.72% (0.13718) | 96.39th | v5 (v2026.06.15) |
| Jun 15, 2026 | 13.72% (0.13718) | 96.01th | v5 (v2026.06.15) |
| Jan 15, 2026 | 13.07% (0.13072) | 93.88th | v4 (v2025.03.14) |
| Dec 28, 2025 | 11.64% (0.11643) | 93.42th | v4 (v2025.03.14) |
| Dec 27, 2025 | 18.67% (0.18666) | 95.08th | v4 (v2025.03.14) |
| Oct 28, 2025 | 11.64% (0.11643) | 93.34th | v4 (v2025.03.14) |
| Oct 27, 2025 | 18.67% (0.18666) | 95.00th | v4 (v2025.03.14) |
| Oct 1, 2025 | 11.64% (0.11643) | 93.44th | v4 (v2025.03.14) |
| Jul 30, 2025 | 18.67% (0.18666) | 95.00th | v4 (v2025.03.14) |
| Jul 16, 2025 | 11.64% (0.11643) | 93.34th | v4 (v2025.03.14) |
| Mar 30, 2025 | 7.93% (0.07933) | 91.24th | v4 (v2025.03.14) |
| Mar 29, 2025 | 17.45% (0.17446) | 91.84th | v4 (v2025.03.14) |
| Mar 17, 2025 | 7.93% (0.07933) | 91.43th | v4 (v2025.03.14) |
| Dec 12, 2024 | 2.62% (0.02621) | 90.70th | v3 (v2023.03.01) |
| Mar 9, 2024 | 2.85% (0.02848) | 90.44th | v3 (v2023.03.01) |
| Feb 15, 2024 | 2.36% (0.02357) | 89.46th | v3 (v2023.03.01) |
| Aug 9, 2023 | 1.98% (0.01978) | 87.29th | v3 (v2023.03.01) |
| Mar 7, 2023 | 2.13% (0.02133) | 87.46th | v3 (v2023.03.01) |
| Mar 6, 2023 | 12.57% (0.12567) | 95.52th | v2 (v2022.01.01) |
| Apr 1, 2022 | 12.57% (0.12567) | 95.18th | v2 (v2022.01.01) |
| Feb 4, 2022 | 12.57% (0.12567) | 90.03th | v2 (v2022.01.01) |
References (24)
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-001.txt.asc vendor-advisoryx_refsource_NETBSDBroken Link
- ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I vendor-advisoryx_refsource_SGIBroken Link
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000570 vendor-advisoryx_refsource_CONECTIVABroken Link
- http://marc.info/?l=bugtraq&m=104567627211904&w=2 mailing-listx_refsource_BUGTRAQThird Party Advisory
- http://marc.info/?l=bugtraq&m=104568426824439&w=2 mailing-listx_refsource_BUGTRAQThird Party Advisory
- http://marc.info/?l=bugtraq&m=104577183206905&w=2 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://www.ciac.org/ciac/bulletins/n-051.shtml third-party-advisorygovernment-resourcex_refsource_CIACBroken Link
- http://www.debian.org/security/2003/dsa-253 vendor-advisoryx_refsource_DEBIANBroken LinkVendor Advisory
- http://www.iss.net/security_center/static/11369.php vdb-entryx_refsource_XFBroken LinkVendor Advisory
- http://www.linuxsecurity.com/advisories/engarde_advisory-2874.html vendor-advisoryx_refsource_ENGARDEBroken Link
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:020 vendor-advisoryx_refsource_MANDRAKEBroken Link
- http://www.openssl.org/news/secadv_20030219.txt x_refsource_CONFIRMBroken LinkPatchVendor Advisory
- http://www.osvdb.org/3945 vdb-entryx_refsource_OSVDBBroken Link
- http://www.redhat.com/support/errata/RHSA-2003-062.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2003-063.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2003-082.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2003-104.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2003-205.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.securityfocus.com/bid/6884 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.trustix.org/errata/2003/0005 vendor-advisoryx_refsource_TRUSTIXBroken Link
- https://access.redhat.com/security/cve/CVE-2003-0078 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1616956 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2003-0078
- https://www.cve.org/CVERecord?id=CVE-2003-0078
Change history (0)
No recorded changes yet.