CVE-2003-0695

Impact:
Critical
Public Date:
2003-09-16
Bugzilla:
1617071: CVE-2003-0695 security flaw

The MITRE CVE dictionary describes this issue as:

Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vulnerability than CVE-2003-0693.

Find out more about CVE-2003-0695 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Not vulnerable.

This flaw is fixed in Red Hat Enterprise Linux 2.1 via the errata RHSA-2003:280.

This flaw is fixed in Red Hat Enterprise Linux 3 as a backported patch. The source RPM contains the patch openssh-3.6.1p2-owl-realloc.diff which resolved this flaw before Red Hat Enterprise Linux 3 GA.

This flaw does not affect any subsequent versions of Red Hat Enterprise Linux.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Linux 8.0 RHSA-2003:279 2003-09-16
Red Hat Linux 7.1 RHSA-2003:279 2003-09-16
Red Hat Linux 9 RHSA-2003:279 2003-09-16
Red Hat Linux 7.2 RHSA-2003:279 2003-09-16
Red Hat Linux 7.3 RHSA-2003:279 2003-09-16
Red Hat Enterprise Linux 2.1 RHSA-2003:280 2003-09-16
Last Modified

CVE description copyright © 2017, The MITRE Corporation