Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Immunix | Immunix | 7.0 (including) | 7.0 (including) |
| Mandrake_single_network_firewall | Mandrakesoft | 7.2 (including) | 7.2 (including) |
| Openssh | Openbsd | 2.0 (including) | 3.1 (excluding) |
| Openpkg | Openpkg | 1.0 (including) | 1.0 (including) |
| Linux | Conectiva | 5.0 (including) | 5.0 (including) |
| Linux | Conectiva | 5.1 (including) | 5.1 (including) |
| Linux | Conectiva | 6.0 (including) | 6.0 (including) |
| Linux | Conectiva | 7.0 (including) | 7.0 (including) |
| Linux | Conectiva | ecommerce (including) | ecommerce (including) |
| Linux | Conectiva | graficas (including) | graficas (including) |
| Red Hat Linux 7.0 | RedHat | * | |
| Red Hat Linux 7.1 | RedHat | * | |
| Red Hat Linux 7.2 | RedHat | * |