CLA-2002:502Vendor advisory
http://distro.conectiva.com.br/atualizacoes?id=a&anuncio=000502 CVE-2002-0640
OpenSSH 3.x - Challenge-Response Buffer Overflow (1)
Record summary
CVE-2002-0640 has a selected CVSS score of 10.0; EIP currently links 2 catalogued exploits.
Description
Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses during challenge response authentication when OpenBSD is using PAM modules with interactive keyboard authentication (PAMAuthenticationViaKbdInt).
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBOpenSSH 3.x - Challenge-Response Buffer Overflow (1)ExploitDB exploitby Christophe DevineNot analyzed1 file
ExploitDBOpenSSH 3.x - Challenge-Response Buffer Overflow (2)ExploitDB exploitby Gobbles SecurityNot analyzed1 file
References
Showing 12 of 1820020626 OpenSSH Security Advisory (adv.iss)mailing list
http://marc.info/?l=bugtraq&m=102514371522793&w=2 20020626 Revised OpenSSH Security Advisory (adv.iss)mailing list
http://marc.info/?l=bugtraq&m=102514631524575&w=2 20020627 How to reproduce OpenSSH Overflow.mailing list
http://marc.info/?l=bugtraq&m=102521542826833&w=2 20020628 Sun statement on the OpenSSH Remote Challenge Vulnerabilitymailing list
http://marc.info/?l=bugtraq&m=102532054613894&w=2 CA-2002-18Third-party advisory
http://www.cert.org/advisories/CA-2002-18.html DSA-134Vendor advisory
http://www.debian.org/security/2002/dsa-134 VU#369347Third-party advisory
http://www.kb.cert.org/vuls/id/369347 ESA-20020702-016Vendor advisory
http://www.linuxsecurity.com/advisories/other_advisory-2177.html MDKSA-2002:040Vendor advisory
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:040 SuSE-SA:2002:024Vendor advisory
http://www.novell.com/linux/security/advisories/2002_024_openssh_txt.html [oss-security] 20240701 CVE-2024-6387: RCE in OpenSSH's server, on glibc-based Linux systemsmailing list
http://www.openwall.com/lists/oss-security/2024/07/01/3