Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2003-0386 | First vendor Publication | 2003-07-02 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to bypass "from=" and "user@host" address restrictions by connecting to a host from a system whose reverse DNS hostname contains the numeric IP address. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0386 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:9894 | |||
Oval ID: | oval:org.mitre.oval:def:9894 | ||
Title: | OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to bypass "from=" and "user@host" address restrictions by connecting to a host from a system whose reverse DNS hostname contains the numeric IP address. | ||
Description: | OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to bypass "from=" and "user@host" address restrictions by connecting to a host from a system whose reverse DNS hostname contains the numeric IP address. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2003-0386 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
2112 | OpenSSH Reverse DNS Lookup Bypass OpenSSH could allow a remote attacker to gain unauthorized access to the network. If the 'VeriftyReverseMapping' flag is disabled, which is the default setting, a remote attacker using their own DNS (Domain Name System) server to control reverse lookup responses can employ DNS spoofing techniques to bypass login restrictions and gain unauthorized access to the network. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2011-08-29 | Name : The SSH service running on the remote host has an information disclosure vuln... File : sunssh_plaintext_recovery.nasl - Type : ACT_GATHER_INFO |
2006-09-29 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2006-0698.nasl - Type : ACT_GATHER_INFO |
2006-08-04 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2006-0298.nasl - Type : ACT_GATHER_INFO |
2006-07-21 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2006-0298.nasl - Type : ACT_GATHER_INFO |
2003-06-10 | Name : The remote host has an application that is affected by DNS lookup bypass vuln... File : openssh_rev_dns_lookup_bypass.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:23:28 |
|
2024-11-28 12:05:36 |
|
2024-08-02 12:02:30 |
|
2024-08-02 01:01:25 |
|
2024-02-02 01:02:16 |
|
2024-02-01 12:01:26 |
|
2023-09-05 12:02:10 |
|
2023-09-05 01:01:18 |
|
2023-09-02 12:02:11 |
|
2023-09-02 01:01:18 |
|
2023-08-12 12:02:41 |
|
2023-08-12 01:01:18 |
|
2023-08-11 12:02:17 |
|
2023-08-11 01:01:19 |
|
2023-08-06 12:02:06 |
|
2023-08-06 01:01:19 |
|
2023-08-04 12:02:10 |
|
2023-08-04 01:01:19 |
|
2023-07-14 12:02:08 |
|
2023-07-14 01:01:19 |
|
2023-03-29 01:02:06 |
|
2023-03-28 12:01:24 |
|
2022-10-11 12:01:54 |
|
2022-10-11 01:01:12 |
|
2021-05-04 12:01:58 |
|
2021-04-22 01:02:09 |
|
2020-07-25 12:01:13 |
|
2020-05-23 00:15:24 |
|
2017-10-11 09:23:17 |
|
2016-04-26 12:33:09 |
|
2014-02-17 10:26:11 |
|
2013-05-11 11:51:17 |
|