CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2002-0639

CVSS 9.8v3.1pub. 2002-07-03upd. 2026-04-16

Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Openbsd OpenSSH

    APP
    Openbsd
    2.9.9 – 3.3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2023-38408CRITICAL9.8PL ✓same product

RCE w OpenSSH ssh-agent przez niezaufaną ścieżkę ładowania PKCS#11

CVE-2023-28531CRITICAL9.8PL ✓same product

OpenSSH ssh-add: brak ograniczeń destination constraints dla kluczy smartcard

CVE-2016-1908CRITICAL9.8PL ✓same product

OpenSSH: pominięcie kontroli dostępu w przekierowaniu X11 (Auth Bypass)

CVE-2010-4478CRITICAL9.8PL ✓same product

OpenSSH J-PAKE — pominięcie uwierzytelnienia przez nieprawidłowe parametry

CVE-2002-0083CRITICAL9.8PL ✓same product

OpenSSH: błąd off-by-one w kodzie kanałów umożliwia eskalację uprawnień