Vulnerability Description
Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openbsd | Openssh | >= 2.9.9, <= 3.3 |
Related Weaknesses (CWE)
References
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-030.0.txtBroken Link
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0335.htmlBroken Link
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000502Broken Link
- http://marc.info/?l=bugtraq&m=102514371522793&w=2ExploitMailing List
- http://marc.info/?l=bugtraq&m=102514631524575&w=2ExploitMailing List
- http://marc.info/?l=bugtraq&m=102521542826833&w=2ExploitMailing List
- http://www.cert.org/advisories/CA-2002-18.htmlThird Party AdvisoryUS Government Resource
- http://www.debian.org/security/2002/dsa-134Broken Link
- http://www.iss.net/security_center/static/9169.phpBroken Link
- http://www.kb.cert.org/vuls/id/369347Third Party AdvisoryUS Government Resource
- http://www.linuxsecurity.com/advisories/other_advisory-2177.htmlBroken Link
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:040Broken Link
- http://www.osvdb.org/6245Broken Link
- http://www.securityfocus.com/bid/5093Broken LinkThird Party AdvisoryVDB Entry
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0206-195Broken Link
FAQ
What is CVE-2002-0639?
CVE-2002-0639 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using...
How severe is CVE-2002-0639?
CVE-2002-0639 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2002-0639?
Check the references section above for vendor advisories and patch information. Affected products include: Openbsd Openssh.