VDB
CVE-2003-0686
CVE-2003-0686
PUBLISHED
CVSS 7.5 HIGH
Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote attackers to execute arbitrary code.
EPSS 49.33% · 97.8th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
49.33%
97.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | pam_smb | 1.1.6-7, 1.1.6-2, 1.1.6-2 |
| dave_airlie | pam_smb | 1.1.5, 1.1.6, 1.1 |
| n/a | n/a | n/a |
Timeline
- Sep 3, 2003 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- http://us2.samba.org/samba/ftp/pam_smb/ url
- CLA-2003:734 vendor-advisory
- RHSA-2003:261 vendor-advisory
- 20030901 GLSA: pam_smb (200309-01) mailing-list
- RHSA-2003:262 vendor-advisory
- VU#680260 third-party-advisory
- 9611 third-party-advisory
- DSA-374 vendor-advisory
- oval:org.mitre.oval:def:469 vdb
- TLSA-2003-50 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2003-0686 advisory
- http://us2.samba.org/samba/ftp/pam_smb url