CVE-2003-0147

Source
https://nvd.nist.gov/vuln/detail/CVE-2003-0147
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2003-0147.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2003-0147
Downstream
Published
2003-03-31T05:00:00Z
Modified
2025-08-09T20:01:26Z
Summary
[none]
Details

OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal).

References

Affected packages