CVE detail
CVE-2003-0826 — CVE-2003-0826
Published 2003-10-06 · Modified 2026-06-16 · Vendor gnu · Product lsh · Source nvd
UNKNOWN
severity
CVSS-derived band
0.1211
EPSS probability
exploitation probability, 30d
96.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
lsh daemon (lshd) does not properly return from certain functions in (1) read_line.c, (2) channel_commands.c, or (3) client_keyexchange.c when long input is provided, which could allow remote attackers to execute arbitrary code via a heap-based buffer overflow attack.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References