CVE Vulnerabilities

CVE-2003-0386

Published: Jul 02, 2003 | Modified: Nov 20, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to bypass from= and user@host address restrictions by connecting to a host from a system whose reverse DNS hostname contains the numeric IP address.

Affected Software

Name Vendor Start Version End Version
Openssh Openbsd 3.6.1 (including) 3.6.1 (including)
Red Hat Enterprise Linux 2.1 RedHat openssh-0:3.1p1-21 *
Red Hat Enterprise Linux 3 RedHat openssh-0:3.6.1p2-33.30.9 *

References