VDB
CVE-2003-0787
CVE-2003-0787
PUBLISHED
CVSS 7.5 HIGH
The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modify the stack and possibly gain privileges.
EPSS 0.46% · 64.7th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
0.46%
64.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| openbsd | openssh | 3.7.1, 3.7.1p1 |
| n/a | n/a | * |
Timeline
- Sep 25, 2003 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Apr 29, 2022 CVE Updated
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- http://www.openssh.com/txt/sshpam.adv url
- 8677 vdb
- VU#209807 third-party-advisory
- 20030923 Multiple PAM vulnerabilities in portable OpenSSH mailing-list
- 20030923 Portable OpenSSH 3.7.1p2 released mailing-list
- 20030924 [OpenPKG-SA-2003.042] OpenPKG Security Advisory (openssh) mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2003-0787 advisory