First published: Tue Jun 10 2003(Updated: )
OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to bypass "from=" and "user@host" address restrictions by connecting to a host from a system whose reverse DNS hostname contains the numeric IP address.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenSSH | =3.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0386 is considered a moderate severity vulnerability due to its potential to allow unauthorized access to systems.
To fix CVE-2003-0386, upgrade OpenSSH to version 3.6.2 or later, which addresses this vulnerability.
CVE-2003-0386 affects OpenSSH version 3.6.1 and earlier when reverse DNS mapping is disabled.
Yes, CVE-2003-0386 can be exploited remotely by attackers who can manipulate reverse DNS entries.
The primary risk of CVE-2003-0386 is that it allows remote attackers to bypass specific host access restrictions.