CVE-2002-0639
Published · Updated
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 18%
exploitation probability
18%top 3% of all CVEs
observed exploitation
nono source reports it
Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication.
Affected products
n/a · n/aReferences
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-030.0.txthttp://archives.neohapsis.com/archives/bugtraq/2002-06/0335.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000502http://marc.info/?l=bugtraq&m=102514371522793&w=2http://marc.info/?l=bugtraq&m=102514631524575&w=2http://marc.info/?l=bugtraq&m=102521542826833&w=2https://twitter.com/RooneyMcNibNug/status/1152332585349111810https://web.archive.org/web/20080622172542/www.iss.net/threats/advise123.htmlhttp://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0206-195http://www.cert.org/advisories/CA-2002-18.htmlhttp://www.debian.org/security/2002/dsa-134http://www.iss.net/security_center/static/9169.php