VDB
CVE-2003-0386
CVE-2003-0386
PUBLISHED
CVSS 7.5 HIGH
OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to bypass "from=" and "user@host" address restrictions by connecting to a host from a system whose reverse DNS hostname contains the numeric IP address.
EPSS 5.77% · 92.8th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
5.77%
92.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| openbsd | openssh | 3.6.1 |
Timeline
- Jun 10, 2003 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- May 27, 2023 EPSS Score
- Jul 19, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
- Dec 24, 2023 EPSS Score
References
- None advisory
- RHSA-2006:0298 vendor-advisory
- http://support.avaya.com/elmodocs2/security/ASA-2006-174.htm url
- oval:org.mitre.oval:def:9894 vdb
- http://lists.apple.com/mhonarc/security-announce/msg00038.html url
- https://nvd.nist.gov/vuln/detail/CVE-2003-0386 advisory
- http://secunia.com/advisories/21724 url
- http://secunia.com/advisories/23680 url
- http://www.redhat.com/support/errata/RHSA-2006-0698.html url
- http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html url
- http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html url
- http://secunia.com/advisories/21129 technical
- http://secunia.com/advisories/22196 technical
- http://www.kb.cert.org/vuls/id/978316 exploit
- http://www.securityfocus.com/archive/1/324016/2003-06-03/2003-06-09/0 exploit
- http://www.securityfocus.com/bid/7831 technical
- ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc technical
- http://secunia.com/advisories/21262 technical