PT-2003-1107 · Openssh+1 · Openssh+5

David Mirza Ahmad

·

Publicado

2003-09-16

·

Atualizado

2024-07-08

·

CVE-2003-0693

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSH versions prior to 3.7 OpenSSH-server versions 3.1p1 through 3.4p1 OpenSSH-askpass versions 3.1p1 through 3.4p1 OpenSSH-askpass-gnome versions 3.1p1 through 3.4p1 OpenSSH-clients versions 3.1p1 through 3.4p1
Description The issue is related to multiple vulnerabilities in OpenSSH, which can lead to disruption of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be done remotely. A "buffer management error" in buffer append space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap.
Recommendations For OpenSSH versions prior to 3.7, update to version 3.7 or later. For OpenSSH-server versions 3.1p1 through 3.4p1, update to version 3.7 or later. For OpenSSH-askpass versions 3.1p1 through 3.4p1, update to version 3.7 or later. For OpenSSH-askpass-gnome versions 3.1p1 through 3.4p1, update to version 3.7 or later. For OpenSSH-clients versions 3.1p1 through 3.4p1, update to version 3.7 or later. As a temporary workaround, consider restricting access to the vulnerable OpenSSH components until a patch is available.

Exploit

Correção

Side Channel Attack

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
BDU:2015-08184
BDU:2015-08185
BDU:2015-08187
BDU:2015-08188
BDU:2015-08190
BDU:2015-08191
BDU:2015-08193
BDU:2015-08194
BDU:2015-08196
BDU:2015-08197
CVE-2003-0693
DSA-382
DSA-383

Produtos afetados

Alt Linux
Openssh
Openssh-Askpass
Openssh-Askpass-Gnome
Openssh-Clients
Openssh-Server