Vulnerabilities > CVE-2003-0682 - Unspecified vulnerability in Openbsd Openssh
"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.
Vulnerable Configurations
NASL family Red Hat Local Security Checks
NASL id REDHAT-RHSA-2003-280.NASL
description Updated OpenSSH packages are now available that fix bugs that may be remotely exploitable.

[Updated 17 Sep 2003]
Updated packages are now available to fix additional buffer manipulation problems which were fixed in OpenSSH 3.7.1. The Common Vulnerabilities and Exposures project ( has assigned the name CVE-2003-0695 to these additional issues.

We have also included fixes from Solar Designer for some additional memory bugs. The Common Vulnerabilities and Exposures project ( has assigned the name CVE-2003-0682 to these issues.

OpenSSH is a suite of network connectivity tools that can be used to establish encrypted connections between systems on a network and can provide interactive login sessions and port forwarding, among other functions.

The OpenSSH team has announced a bug which affects the OpenSSH buffer handling code. This bug has the potential of being remotely exploitable. We have also included fixes from Solar Designer for some additional memory bugs. The Common Vulnerabilities and Exposures project ( has assigned the name CVE-2003-0682 to these issues.

OpenSSH is a suite of network connectivity tools that can be used to establish encrypted connections between systems on a network and can provide interactive login sessions and port forwarding, among other functions.

The OpenSSH team has announced a bug which affects the OpenSSH buffer handling code. This bug has the potential of being remotely exploitable.

The Common Vulnerabilities and Exposures project ( has assigned the name CVE-2003-0693 to this issue. NASL family Debian Local Security Checks
NASL id DEBIAN_DSA-382.NASL
description A bug has been found in OpenSSH

NASL family Misc.
NASL id SUNSSH_PLAINTEXT_RECOVERY.NASL
description The version of SunSSH running on the remote host has an information disclosure vulnerability. A design flaw in the SSH specification could allow a man-in-the-middle attacker to recover up to 32 bits of plaintext from an SSH-protected connection in the standard configuration. An attacker could exploit this to gain access to sensitive information.

Note that this version of SunSSH is also prone to several additional issues but Nessus did not test for them.

NASL family Red Hat Local Security Checks
NASL id REDHAT_FIXES.NASL
description This plugin writes in the knowledge base the CVE ids that we know Red Hat enterprise Linux is not vulnerable to.

NASL family Debian Local Security Checks
NASL id DEBIAN_DSA-383.NASL
description Several bugs have been found in OpenSSH

NASL family Gain a shell remotely
NASL id OPENSSH_36.NASL
description According to its banner, the remote SSH server is running a version of OpenSSH older than 3.7.1. Such versions are vulnerable to a flaw in the buffer management functions that might allow an attacker to execute arbitrary commands on this host.

An exploit for this issue is rumored to exist.

Note that several distributions patched this hole without changing the version number of OpenSSH. Since Nessus solely relied on the banner of the remote SSH server to perform this check, this might be a false positive.
description | "Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.
title | Memory Bugs in OpenSSH
advisories |
contributor | Joshua Bressers |
lastmodified | 2007-03-27 |
organization | Red Hat |
statement | Not vulnerable. This flaw is fixed in Red Hat Enterprise Linux 2.1 via the errata RHSA-2003:280. This flaw is fixed in Red Hat Enterprise Linux 3 as a backported patch. The source RPM contains the patch openssh-3.6.1p2-owl-realloc.diff which resolved this flaw before Red Hat Enterprise Linux 3 GA. This flaw does not affect any subsequent versions of Red Hat Enterprise Linux. |