CVE-2003-0693Improper Restriction of Operations within the Bounds of a Memory Buffer in Openssh

Severity
10.0CRITICALNVD
EPSS
26.8%
top 3.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 22
Latest updateApr 29

Description

A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

Debianopenbsd/openssh< 1:3.6.1p2-6.0+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-2264-54r3-3rjm: A "buffer management error" in buffer_append_space of buffer2022-04-29
OSV
CVE-2003-0693: A "buffer management error" in buffer_append_space of buffer2003-09-22
CVEList
CVE-2003-0693: A "buffer management error" in buffer_append_space of buffer2003-09-17

📋Vendor Advisories

5
Cisco
OpenSSH Server Vulnerabilities2003-09-17
Red Hat
security flaw2003-09-16
Red Hat
security flaw2003-09-16
Red Hat
security flaw2003-09-15
Debian
CVE-2003-0693: openssh - A "buffer management error" in buffer_append_space of buffer.c for OpenSSH befor...2003

💬Community

3
Bugzilla
CVE-2003-0693 security flaw2018-08-16
Bugzilla
CVE-2003-0682 security flaw2018-08-16
Bugzilla
CVE-2003-0695 security flaw2018-08-16
CVE-2003-0693 — Openbsd Openssh vulnerability | cvebase