CVE-2002-0639

CRITICAL

Openbsd Openssh < 3.3 - Integer Overflow

Title source: rule

Description

Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication.

Scores

CVSS v3 9.8
EPSS 0.3371
EPSS Percentile 96.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-190
Status draft

Affected Products (1)

openbsd/openssh < 3.3

Timeline

Published Jul 03, 2002
Tracked Since Feb 18, 2026