CVE-2003-0386
Last modified
CVE-2003-0386 is a vulnerability of currently unknown severity. OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to bypass "from=" and "user@host" address restrictions by connecting to a host from a system whose reverse DNS hostname contains the numeric IP address.. EPSS estimates a 5.77% chance of exploitation in the next 30 days.
Description
OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to bypass "from=" and "user@host" address restrictions by connecting to a host from a system whose reverse DNS hostname contains the numeric IP address.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openbsd | Openssh | 3.6.1 |
References
- http://www.kb.cert.org/vuls/id/978316Exploit, Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/archive/1/324016/2003-06-03/2003-06-09/0Exploit, Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/978316Exploit, Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/archive/1/324016/2003-06-03/2003-06-09/0Exploit, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-0386?
How severe is CVE-2003-0386?
How do I fix CVE-2003-0386?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2003
- CVE-2003-0378The Kerberos login authentication feature in Mac OS X, when …
- CVE-2003-0379Unknown vulnerability in Apple File Service (AFP Server) for…
- CVE-2003-0380Buffer overflow in atftp daemon (atftpd) 0.6.1 and earlier, …
- CVE-2003-0381Multiple vulnerabilities in noweb 2.9 and earlier creates te…
- CVE-2003-0382Buffer overflow in Eterm 0.9.2 allows local users to gain pr…
- CVE-2003-0385Buffer overflow in xaos 3.0-23 and earlier, when running set…
- CVE-2003-0388pam_wheel in Linux-PAM 0.78, with the trust option enabled a…
- CVE-2003-0389Cross-site scripting (XSS) vulnerability in the secure redir…
- CVE-2003-0390Multiple buffer overflows in Options Parsing Tool (OPT) shar…
- CVE-2003-0391Format string vulnerability in Magic WinMail Server 2.3, and…
- CVE-2003-0392Directory traversal vulnerability in ST FTP Service 3.0 allo…
- CVE-2003-0393Privacyware Privatefirewall 3.0 does not block certain incom…
Are you affected by CVE-2003-0386?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
