CVE Vulnerabilities

CVE-2002-0083

Off-by-one Error

Published: Mar 15, 2002 | Modified: Nov 20, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.

Weakness

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

Affected Software

Name Vendor Start Version End Version
Immunix Immunix 7.0 (including) 7.0 (including)
Mandrake_single_network_firewall Mandrakesoft 7.2 (including) 7.2 (including)
Openssh Openbsd 2.0 (including) 3.1 (excluding)
Openpkg Openpkg 1.0 (including) 1.0 (including)
Linux Conectiva 5.0 (including) 5.0 (including)
Linux Conectiva 5.1 (including) 5.1 (including)
Linux Conectiva 6.0 (including) 6.0 (including)
Linux Conectiva 7.0 (including) 7.0 (including)
Linux Conectiva ecommerce (including) ecommerce (including)
Linux Conectiva graficas (including) graficas (including)
Red Hat Linux 7.0 RedHat *
Red Hat Linux 7.1 RedHat *
Red Hat Linux 7.2 RedHat *

Potential Mitigations

References