CVE-2002-0639

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
03/07/2002
Last modified:
03/04/2025

Description

Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* 2.9.9 (including) 3.3 (including)


References to Advisories, Solutions, and Tools