PT-2002-2368 · Ssh · Ssh Secure Shell For Servers+1
Published
2002-11-25
·
Updated
2017-07-11
·
CVE-2002-1644
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SSH Secure Shell for Servers and SSH Secure Shell for Workstations versions 2.0.13 through 3.2.1
Description
The issue allows attackers to gain certain privileges when the software is running without a PTY, as it does not call setsid to remove the child process from the process group of the parent process.
Recommendations
For versions 2.0.13 through 3.2.1, consider running the software with a PTY to mitigate the risk of exploitation. As a temporary workaround, restrict access to the affected systems until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ssh Secure Shell For Servers
Ssh Secure Shell For Workstations