Unrated severityNVD Advisory· Published Mar 24, 2003· Updated Jun 16, 2026
CVE-2003-0131
CVE-2003-0131
Description
The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the "Klima-Pokorny-Rosa attack."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12cpe:2.3:a:openssl:openssl:0.9.6:*:*:*:*:*:*:*+ 11 more
- cpe:2.3:a:openssl:openssl:0.9.6:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.6a:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.6b:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.6c:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.6d:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.6e:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.6g:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.6h:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.6i:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.7:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.7a:*:*:*:*:*:*:*
- (no CPE)range: <=0.9.6i, 0.9.7, 0.9.7a
Patches
Vulnerability mechanics
References
23- www.securityfocus.com/bid/7148nvdPatchVendor Advisory
- eprint.iacr.org/2003/052/nvdVendor Advisory
- www.kb.cert.org/vuls/id/888801nvdThird Party AdvisoryUS Government Resource
- ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-007.txt.ascnvd
- ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txtnvd
- patches.sgi.com/support/free/security/advisories/20030501-01-Invd
- distro.conectiva.com.br/atualizacoes/nvd
- lists.apple.com/mhonarc/security-announce/msg00028.htmlnvd
- marc.infonvd
- marc.infonvd
- marc.infonvd
- www.debian.org/security/2003/dsa-288nvd
- www.gentoo.org/security/en/glsa/glsa-200303-20.xmlnvd
- www.linuxsecurity.com/advisories/immunix_advisory-3066.htmlnvd
- www.mandriva.com/security/advisoriesnvd
- www.openpkg.org/security/OpenPKG-SA-2003.026-openssl.htmlnvd
- www.openssl.org/news/secadv_20030319.txtnvd
- www.redhat.com/support/errata/RHSA-2003-101.htmlnvd
- www.redhat.com/support/errata/RHSA-2003-102.htmlnvd
- www.securityfocus.com/archive/1/316577/30/25310/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/11586nvd
- lists.opensuse.org/opensuse-security-announce/2003-04/msg00005.htmlnvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A461nvd
News mentions
0No linked articles in our index yet.