CVE-2002-1359

Multiple SSH2 - Buffer Overflow

Title source: llm

Description

Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16463
exploitdb WORKING POC VERIFIED
by y0 · remotewindows
https://www.exploit-db.com/exploits/1788
metasploit WORKING POC NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/ssh/putty_msg_debug.rb

Scores

EPSS 0.8700
EPSS Percentile 99.4%

Details

CWE
CWE-20
Status published
Products (16)
cisco/ios 12.0s
cisco/ios 12.0st
cisco/ios 12.1e
cisco/ios 12.1ea
cisco/ios 12.1t
cisco/ios 12.2
cisco/ios 12.2s
cisco/ios 12.2t
fissh/ssh_client 1.0a_for_windows
intersoft/securenetterm 5.4.1
... and 6 more
Published Dec 23, 2002
Tracked Since Feb 18, 2026