Loading
OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal).
Use Openpkg vendor hub and Openpkg product page to widen CVE-2003-0147 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2004-0990, CVE-2004-1065 and CVE-2004-1019 for nearby disclosures in the same product family.