CVE-2003-0693

OpenSSH < 3.7 - Remote Code Execution via Buffer Management Error

Title source: llm
STIX 2.1

Description

A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.

References (20)

Core 20
Core References
Third Party Advisory, VDB Entry vdb-entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/13191
Third Party Advisory vendor-advisory
http://www.debian.org/security/2003/dsa-383
US Government Resource third-party-advisory
http://www.cert.org/advisories/CA-2003-24.html
Third Party Advisory vendor-advisory
http://www.debian.org/security/2003/dsa-382
Patch, Third Party Advisory, US Government Resource third-party-advisory
http://www.kb.cert.org/vuls/id/333628

Scores

EPSS 0.2682
EPSS Percentile 96.4%

Details

Status published
Products (1)
openbsd/openssh < 3.7
Published Sep 22, 2003
Tracked Since Feb 18, 2026