CVE-2002-0083
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 15%
from disclosure to weapon0 days
Published on NVDJun 25
1st PoCMar 7
exploitation probability
15%top 4% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/21314⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:13.openssh.ascftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-004.txt.ascftp://stage.caldera.com/pub/security/openserver/CSSA-2002-SCO.10/CSSA-2002-SCO.10.txtftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.11/CSSA-2002-SCO.11.txthttp://archives.neohapsis.com/archives/bugtraq/2002-03/0108.htmlhttp://archives.neohapsis.com/archives/vulnwatch/2002-q1/0060.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000467http://marc.info/?l=bugtraq&m=101552065005254&w=2http://marc.info/?l=bugtraq&m=101553908201861&w=2http://marc.info/?l=bugtraq&m=101561384821761&w=2http://marc.info/?l=bugtraq&m=101586991827622&w=2http://online.securityfocus.com/advisories/3960