CVE-2003-0078

Source
https://nvd.nist.gov/vuln/detail/CVE-2003-0078
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2003-0078.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2003-0078
Downstream
Published
2003-03-03T05:00:00Z
Modified
2025-08-09T19:01:28Z
Summary
[none]
Details

ssl3getrecord in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack."

References

Affected packages