PT-2002-1073 · Openssh+2 · Openssh+2

Published

2002-03-15

·

Updated

2024-07-08

·

CVE-2002-0083

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSH versions 2.0 through 3.0.2 openssh-askpass-3.1p1 openssh-askpass-gnome-3.1p1 openssh-clients-3.1p1 openssh-server-3.1p1 openssh-3.1p1
Description The issue is related to an off-by-one error in the channel code of OpenSSH, allowing local users or remote malicious servers to gain privileges. Multiple vulnerabilities in the openssh package of Red Hat Linux can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations For OpenSSH versions 2.0 through 3.0.2, update to a version later than 3.0.2 to resolve the issue. For openssh-askpass-3.1p1, consider disabling the package until a patch is available. For openssh-askpass-gnome-3.1p1, restrict access to the package to minimize the risk of exploitation. For openssh-clients-3.1p1, avoid using the package for remote connections until the issue is resolved. For openssh-server-3.1p1, restrict access to the server to minimize the risk of exploitation. For openssh-3.1p1, consider disabling the package until a patch is available.

Exploit

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
BDU:2015-08184
BDU:2015-08187
BDU:2015-08190
BDU:2015-08193
BDU:2015-08196
CVE-2002-0083

Affected Products

Alt Linux
Openssh
Red Hat