CVE-2003-0826
lsh-utils - buffer overflow, typo
EPSS 11.8%
Description
lsh daemon (lshd) does not properly return from certain functions in (1) read_line.c, (2) channel_commands.c, or (3) client_keyexchange.c when long input is provided, which could allow remote attackers to execute arbitrary code via a heap-based buffer overflow attack.
How to fix CVE-2003-0826
To remediate CVE-2003-0826, upgrade the affected package to a fixed version below.
- Debian/lsh-utils—upgrade to 1.4.2-6 or later
- Debian/lsh-utils—upgrade to 1.2.5-2woody3 or later
Is CVE-2003-0826 being exploited?
Moderate — EPSS is 11.8%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 1.4.2-6
- from 0, < 1.2.5-2woody3