PT-2002-1676 · Openssh+1 · Openssh+1

Published

2002-07-03

·

Updated

2025-08-07

·

CVE-2002-0639

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSH versions 2.9.9 through 3.3
Description An integer overflow in sshd within OpenSSH versions 2.9.9 through 3.3 can allow remote attackers to execute arbitrary code during ChallengeResponseAuthentication when OpenSSH is configured to use SKEY or BSD AUTH authentication methods.
Recommendations For OpenSSH version 2.9.9 through 3.3, update to a newer, unaffected version.

Exploit

Fix

RCE

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
CVE-2002-0639

Affected Products

Alt Linux
Openssh