Lucene search

K
cveMitreCVE-2003-0787
HistoryNov 17, 2003 - 5:00 a.m.

CVE-2003-0787

2003-11-1705:00:00
mitre
web.nvd.nist.gov
42
cve-2003-0787
openssh
pam
conversation function
vulnerability
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

9.5

Confidence

High

EPSS

0.009

Percentile

83.3%

The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modify the stack and possibly gain privileges.

Affected configurations

Nvd
Node
openbsdopensshMatch3.7.1
OR
openbsdopensshMatch3.7.1p1
VendorProductVersionCPE
openbsdopenssh3.7.1cpe:2.3:a:openbsd:openssh:3.7.1:*:*:*:*:*:*:*
openbsdopenssh3.7.1p1cpe:2.3:a:openbsd:openssh:3.7.1p1:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

9.5

Confidence

High

EPSS

0.009

Percentile

83.3%