CVE-2003-0147

OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal).

Published: 2003-03-31 Last update: 2026-04-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2003-0147 is rated Moderate Risk (55.8/100): CVSS Medium severity, with high exploitation likelihood (EPSS 28.74%, 96th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +2.05% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2003-0147

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-02-27 26.68% 28.74% +2.05%
2 2026-01-28 24.49% 26.68% +2.19%
3 2026-01-20 24.49%

Full EPSS history (21 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2003-0147

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.0 2.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
10.0 2.9 [email protected]

Weakness enumeration for CVE-2003-0147

OS Trackers for CVE-2003-0147

vendor priority summary link
debian not yet assigned CVE-2003-0147 not yet assigned priority: Debian including 1 source packages (openssl), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2003-0147
redhat high https://access.redhat.com/security/cve/CVE-2003-0147
ubuntu medium CVE-2003-0147 medium priority: Ubuntu including 2 source packages (openssl, openssl097), 8 status rows across 4 suites (dapper, edgy, feisty, upstream): released 6, needs-triage 2. https://ubuntu.com/security/CVE-2003-0147

Vendor comments (NVD) for CVE-2003-0147

  • Red Hat (2007-03-14T00:00:00)

    Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

Affected software / configurations for CVE-2003-0147

Vendor Product Version Raw CPE
openpkg openpkg cpe:2.3:a:openpkg:openpkg:*:*:*:*:*:*:*:*
openpkg openpkg 1.1 cpe:2.3:a:openpkg:openpkg:1.1:*:*:*:*:*:*:*
openpkg openpkg 1.2 cpe:2.3:a:openpkg:openpkg:1.2:*:*:*:*:*:*:*
openssl openssl 0.9.6 cpe:2.3:a:openssl:openssl:0.9.6:*:*:*:*:*:*:*
openssl openssl 0.9.6a cpe:2.3:a:openssl:openssl:0.9.6a:*:*:*:*:*:*:*
openssl openssl 0.9.6b cpe:2.3:a:openssl:openssl:0.9.6b:*:*:*:*:*:*:*
openssl openssl 0.9.6c cpe:2.3:a:openssl:openssl:0.9.6c:*:*:*:*:*:*:*
openssl openssl 0.9.6d cpe:2.3:a:openssl:openssl:0.9.6d:*:*:*:*:*:*:*
openssl openssl 0.9.6e cpe:2.3:a:openssl:openssl:0.9.6e:*:*:*:*:*:*:*
openssl openssl 0.9.6g cpe:2.3:a:openssl:openssl:0.9.6g:*:*:*:*:*:*:*
openssl openssl 0.9.6h cpe:2.3:a:openssl:openssl:0.9.6h:*:*:*:*:*:*:*
openssl openssl 0.9.6i cpe:2.3:a:openssl:openssl:0.9.6i:*:*:*:*:*:*:*
openssl openssl 0.9.7 cpe:2.3:a:openssl:openssl:0.9.7:*:*:*:*:*:*:*
openssl openssl 0.9.7a cpe:2.3:a:openssl:openssl:0.9.7a:*:*:*:*:*:*:*
stunnel stunnel 3.7 cpe:2.3:a:stunnel:stunnel:3.7:*:*:*:*:*:*:*
stunnel stunnel 3.8 cpe:2.3:a:stunnel:stunnel:3.8:*:*:*:*:*:*:*
stunnel stunnel 3.9 cpe:2.3:a:stunnel:stunnel:3.9:*:*:*:*:*:*:*
stunnel stunnel 3.10 cpe:2.3:a:stunnel:stunnel:3.10:*:*:*:*:*:*:*
stunnel stunnel 3.11 cpe:2.3:a:stunnel:stunnel:3.11:*:*:*:*:*:*:*
stunnel stunnel 3.12 cpe:2.3:a:stunnel:stunnel:3.12:*:*:*:*:*:*:*
stunnel stunnel 3.13 cpe:2.3:a:stunnel:stunnel:3.13:*:*:*:*:*:*:*
stunnel stunnel 3.14 cpe:2.3:a:stunnel:stunnel:3.14:*:*:*:*:*:*:*
stunnel stunnel 3.15 cpe:2.3:a:stunnel:stunnel:3.15:*:*:*:*:*:*:*
stunnel stunnel 3.16 cpe:2.3:a:stunnel:stunnel:3.16:*:*:*:*:*:*:*
stunnel stunnel 3.17 cpe:2.3:a:stunnel:stunnel:3.17:*:*:*:*:*:*:*
stunnel stunnel 3.18 cpe:2.3:a:stunnel:stunnel:3.18:*:*:*:*:*:*:*
stunnel stunnel 3.19 cpe:2.3:a:stunnel:stunnel:3.19:*:*:*:*:*:*:*
stunnel stunnel 3.20 cpe:2.3:a:stunnel:stunnel:3.20:*:*:*:*:*:*:*
stunnel stunnel 3.21 cpe:2.3:a:stunnel:stunnel:3.21:*:*:*:*:*:*:*
stunnel stunnel 3.22 cpe:2.3:a:stunnel:stunnel:3.22:*:*:*:*:*:*:*
stunnel stunnel 4.0 cpe:2.3:a:stunnel:stunnel:4.0:*:*:*:*:*:*:*
stunnel stunnel 4.01 cpe:2.3:a:stunnel:stunnel:4.01:*:*:*:*:*:*:*
stunnel stunnel 4.02 cpe:2.3:a:stunnel:stunnel:4.02:*:*:*:*:*:*:*
stunnel stunnel 4.03 cpe:2.3:a:stunnel:stunnel:4.03:*:*:*:*:*:*:*
stunnel stunnel 4.04 cpe:2.3:a:stunnel:stunnel:4.04:*:*:*:*:*:*:*

References for CVE-2003-0147

URL Tags
ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txt
ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0130.html Vendor Advisory
http://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000625
http://marc.info/?l=bugtraq&m=104766550528628&w=2
http://marc.info/?l=bugtraq&m=104792570615648&w=2
http://marc.info/?l=bugtraq&m=104819602408063&w=2
http://marc.info/?l=bugtraq&m=104829040921835&w=2
http://marc.info/?l=bugtraq&m=104861762028637&w=2
http://www.debian.org/security/2003/dsa-288
http://www.gentoo.org/security/en/glsa/glsa-200303-23.xml
http://www.kb.cert.org/vuls/id/997481 Third Party Advisory US Government Resource
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:035
http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.019.html
http://www.openssl.org/news/secadv_20030317.txt
http://www.redhat.com/support/errata/RHSA-2003-101.html
http://www.redhat.com/support/errata/RHSA-2003-102.html
http://www.securityfocus.com/archive/1/316165/30/25370/threaded
http://www.securityfocus.com/archive/1/316577/30/25310/threaded
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A466
cvelogic Threat Intelligence