PT-2002-2368 · Ssh · Ssh Secure Shell For Servers+1

Published

2002-11-25

·

Updated

2017-07-11

·

CVE-2002-1644

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SSH Secure Shell for Servers and SSH Secure Shell for Workstations versions 2.0.13 through 3.2.1
Description The issue allows attackers to gain certain privileges when the software is running without a PTY, as it does not call setsid to remove the child process from the process group of the parent process.
Recommendations For versions 2.0.13 through 3.2.1, consider running the software with a PTY to mitigate the risk of exploitation. As a temporary workaround, restrict access to the affected systems until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1644

Affected Products

Ssh Secure Shell For Servers
Ssh Secure Shell For Workstations