CVE-2003-0078 describes a timing discrepancy vulnerability in OpenSSL versions prior to 0.9.7a and 0.9.6i, specifically within the ssl3_get_record function. This flaw, dubbed the "Vaudenay timing attack," arises because the system does not perform a MAC computation if incorrect block cipher padding is detected, potentially allowing attackers to distinguish between padding and MAC verification errors. The vulnerability affects various OpenSSL implementations on FreeBSD and OpenBSD, carrying a CVSS score of 5.0 (Medium) due to its network-based attack vector and potential for information leakage (confidentiality impact). While there is no evidence of active exploitation (KEV: No, Hot List: Inactive), exploit code (EDB-22264) exists, and its EPSS score is relatively low, indicating a lower likelihood of future exploitation. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.9.6iCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
0.9.6iCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.6i:*:*:*:*:*:*:* | ||
0.9.7CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.7:-:*:*:*:*:*:* | ||
0.9.7CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.7:beta1:*:*:*:*:*:* | ||
0.9.7CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.7:beta2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.