CVE Vulnerabilities

CVE-2003-0826

Published: Oct 06, 2003 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

lsh daemon (lshd) does not properly return from certain functions in (1) read_line.c, (2) channel_commands.c, or (3) client_keyexchange.c when long input is provided, which could allow remote attackers to execute arbitrary code via a heap-based buffer overflow attack.

Affected Software

Name Vendor Start Version End Version
Lsh Gnu 1.4 (including) 1.4 (including)
Lsh Gnu 1.4.1 (including) 1.4.1 (including)
Lsh Gnu 1.4.2 (including) 1.4.2 (including)

References