VulnerabilityModified
CVE-2002-0639
Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication.
CRITICAL 9.8EPSS 18.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 18.3%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 18.29% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- openbsd/openssh
- Source
- cve@mitre.org
References
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-030.0.txtBroken Link
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0335.htmlBroken Link
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000502Broken Link
- http://marc.info/?l=bugtraq&m=102514371522793&w=2Exploit, Mailing List
- http://marc.info/?l=bugtraq&m=102514631524575&w=2Exploit, Mailing List
- http://marc.info/?l=bugtraq&m=102521542826833&w=2Exploit, Mailing List
- http://www.cert.org/advisories/CA-2002-18.htmlThird Party Advisory, US Government Resource
- http://www.debian.org/security/2002/dsa-134Broken Link
- http://www.iss.net/security_center/static/9169.phpBroken Link
- http://www.kb.cert.org/vuls/id/369347Third Party Advisory, US Government Resource
- http://www.linuxsecurity.com/advisories/other_advisory-2177.htmlBroken Link
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:040Broken Link
- http://www.osvdb.org/6245Broken Link
- http://www.securityfocus.com/bid/5093Broken Link, Third Party Advisory, VDB Entry
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0206-195Broken Link
- https://twitter.com/RooneyMcNibNug/status/1152332585349111810Broken Link
- https://web.archive.org/web/20080622172542/www.iss.net/threats/advise123.htmlThird Party Advisory
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-030.0.txtBroken Link
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0335.htmlBroken Link
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000502Broken Link
- http://marc.info/?l=bugtraq&m=102514371522793&w=2Exploit, Mailing List
- http://marc.info/?l=bugtraq&m=102514631524575&w=2Exploit, Mailing List
- http://marc.info/?l=bugtraq&m=102521542826833&w=2Exploit, Mailing List
- http://www.cert.org/advisories/CA-2002-18.htmlThird Party Advisory, US Government Resource
- http://www.debian.org/security/2002/dsa-134Broken Link
- http://www.iss.net/security_center/static/9169.phpBroken Link
- http://www.kb.cert.org/vuls/id/369347Third Party Advisory, US Government Resource
- http://www.linuxsecurity.com/advisories/other_advisory-2177.htmlBroken Link
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:040Broken Link
- http://www.osvdb.org/6245Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.