CVE-2002-0639

CRITICAL

OpenSSH 2.9.9-3.3 - Remote Code Execution via Integer Overflow in Challenge Response Authentication

Title source: llm
STIX 2.1

Description

Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication.

References (17)

Core 17
Core References
Broken Link vendor-advisory x_refsource_debian
http://www.debian.org/security/2002/dsa-134
Broken Link vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9169.php
Broken Link mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-06/0335.html
Exploit, Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=102514371522793&w=2
Broken Link vdb-entry x_refsource_osvdb
http://www.osvdb.org/6245
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.cert.org/advisories/CA-2002-18.html
Exploit, Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=102521542826833&w=2
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5093
Broken Link vendor-advisory x_refsource_caldera
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-030.0.txt
Broken Link vendor-advisory x_refsource_engarde
http://www.linuxsecurity.com/advisories/other_advisory-2177.html
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/369347
Broken Link vendor-advisory x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000502
Broken Link vendor-advisory x_refsource_mandrake
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:040
Exploit, Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=102514631524575&w=2
Third Party Advisory third-party-advisory x_refsource_iss
https://web.archive.org/web/20080622172542/www.iss.net/threats/advise123.html

Scores

CVSS v3 9.8
EPSS 0.3371
EPSS Percentile 97.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190
Status published
Products (1)
openbsd/openssh 2.9.9 - 3.3
Published Jul 03, 2002
Tracked Since Feb 18, 2026