The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the "Klima-Pokorny-Rosa attack."
CVSS v2.0 Score
7.5
/ 10.0
HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
Information
- Published
- 24 mars 2003
- Updated
- 16 avr. 2026
- Status
- Modified
- Source
- cve@mitre.org
Affected products
openssl opensslAll OpenSSL CVEs →
Versions : 0.9.6, 0.9.6a, 0.9.6b, 0.9.6c, 0.9.6d
Weaknesses (CWE)
NVD-CWE-Other
References (48)
- http://eprint.iacr.org/2003/052/Vendor Advisory
- http://www.kb.cert.org/vuls/id/888801Third Party AdvisoryUS Government Resource
- + 33 more references on NVD
Monitor your products
Get automatic alerts for every new CVE affecting your equipment.