CVE-2003-0786: Critical severity OpenBSD OpenSSH vulnerability
The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Enable Privilege Separation in OpenSSH so the SSH1 PAM challenge-response authentication result is properly checked (ensure Privilege Separation is not disabled).
OpenSSH Privilege Separation = enabled
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0786?
CVE-2003-0786 is considered a critical vulnerability due to its potential to allow remote attackers to gain elevated privileges.
How do I fix CVE-2003-0786?
The recommended fix for CVE-2003-0786 is to upgrade to a patched version of OpenSSH where Privilege Separation is enabled.
What versions of OpenSSH are affected by CVE-2003-0786?
OpenSSH versions 3.7.1 and 3.7.1p1 are affected by CVE-2003-0786.
Can CVE-2003-0786 result in unauthorized access?
Yes, CVE-2003-0786 can lead to unauthorized access as it allows remote attackers to gain privileges.
Is CVE-2003-0786 related to authentication methods in OpenSSH?
Yes, CVE-2003-0786 specifically involves the SSH1 PAM challenge response authentication method in OpenSSH.