Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2003-0078
Description:ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack."
Test IDs: 1.3.6.1.4.1.25623.1.0.53329   1.3.6.1.4.1.25623.1.0.50686   1.3.6.1.4.1.25623.1.0.52917   1.3.6.1.4.1.25623.1.0.112912   1.3.6.1.4.1.25623.1.0.50986   1.3.6.1.4.1.25623.1.0.54115   1.3.6.1.4.1.25623.1.0.51398   1.3.6.1.4.1.25623.1.0.112911  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2003-0078
BugTraq ID: 6884
http://www.securityfocus.com/bid/6884
Bugtraq: 20030219 OpenSSL 0.9.7a and 0.9.6i released (Google Search)
http://marc.info/?l=bugtraq&m=104567627211904&w=2
Bugtraq: 20030219 [OpenPKG-SA-2003.013] OpenPKG Security Advisory (openssl) (Google Search)
http://marc.info/?l=bugtraq&m=104568426824439&w=2
Computer Incident Advisory Center Bulletin: N-051
http://www.ciac.org/ciac/bulletins/n-051.shtml
Conectiva Linux advisory: CLSA-2003:570
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000570
Debian Security Information: DSA-253 (Google Search)
http://www.debian.org/security/2003/dsa-253
En Garde Linux Advisory: ESA-20030220-005
http://www.linuxsecurity.com/advisories/engarde_advisory-2874.html
FreeBSD Security Advisory: FreeBSD-SA-03:02
http://marc.info/?l=bugtraq&m=104577183206905&w=2
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:020
NETBSD Security Advisory: NetBSD-SA2003-001
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-001.txt.asc
http://www.osvdb.org/3945
RedHat Security Advisories: RHSA-2003:062
http://www.redhat.com/support/errata/RHSA-2003-062.html
RedHat Security Advisories: RHSA-2003:063
http://www.redhat.com/support/errata/RHSA-2003-063.html
RedHat Security Advisories: RHSA-2003:082
http://www.redhat.com/support/errata/RHSA-2003-082.html
RedHat Security Advisories: RHSA-2003:104
http://www.redhat.com/support/errata/RHSA-2003-104.html
RedHat Security Advisories: RHSA-2003:205
http://www.redhat.com/support/errata/RHSA-2003-205.html
SGI Security Advisory: 20030501-01-I
ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I
SuSE Security Announcement: SuSE-SA:2003:011 (Google Search)
http://www.trustix.org/errata/2003/0005
XForce ISS Database: ssl-cbc-information-leak(11369)
http://www.iss.net/security_center/static/11369.php




© 1998-2025 E-Soft Inc. All rights reserved.