PT-2003-1047 · Openssh+1 · Openssh+1

Dan Barrett

+2

·

Published

2003-06-10

·

Updated

2024-07-08

·

CVE-2003-0386

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSH versions 3.6.1 and earlier
Description The issue allows remote attackers to bypass "from=" and "user@host" address restrictions by connecting to a host from a system whose reverse DNS hostname contains the numeric IP address, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of the vulnerabilities can be carried out remotely.
Recommendations For OpenSSH versions 3.6.1 and earlier, consider updating to a newer version to mitigate the risk, as no specific fix is provided for these versions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Double Free

Weakness Enumeration

Related Identifiers

ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
BDU:2015-06465
BDU:2015-06467
BDU:2015-06469
BDU:2015-06471
BDU:2015-06473
CVE-2003-0386
RHSA-2006:0298
RHSA-2006:0698

Affected Products

Alt Linux
Openssh