CVE Vulnerabilities

CVE-2002-0640

Published: Jul 03, 2002 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses during challenge response authentication when OpenBSD is using PAM modules with interactive keyboard authentication (PAMAuthenticationViaKbdInt).

Affected Software

Name Vendor Start Version End Version
Openssh Openbsd 1.2.2 (including) 1.2.2 (including)
Openssh Openbsd 1.2.3 (including) 1.2.3 (including)
Openssh Openbsd 2.1 (including) 2.1 (including)
Openssh Openbsd 2.1.1 (including) 2.1.1 (including)
Openssh Openbsd 2.2 (including) 2.2 (including)
Openssh Openbsd 2.3 (including) 2.3 (including)
Openssh Openbsd 2.5 (including) 2.5 (including)
Openssh Openbsd 2.5.1 (including) 2.5.1 (including)
Openssh Openbsd 2.5.2 (including) 2.5.2 (including)
Openssh Openbsd 2.9 (including) 2.9 (including)
Openssh Openbsd 2.9.9 (including) 2.9.9 (including)
Openssh Openbsd 2.9p1 (including) 2.9p1 (including)
Openssh Openbsd 2.9p2 (including) 2.9p2 (including)
Openssh Openbsd 3.0 (including) 3.0 (including)
Openssh Openbsd 3.0.1 (including) 3.0.1 (including)
Openssh Openbsd 3.0.1p1 (including) 3.0.1p1 (including)
Openssh Openbsd 3.0.2 (including) 3.0.2 (including)
Openssh Openbsd 3.0.2p1 (including) 3.0.2p1 (including)
Openssh Openbsd 3.0p1 (including) 3.0p1 (including)
Openssh Openbsd 3.1 (including) 3.1 (including)
Openssh Openbsd 3.1p1 (including) 3.1p1 (including)
Openssh Openbsd 3.2 (including) 3.2 (including)
Openssh Openbsd 3.2.2p1 (including) 3.2.2p1 (including)
Openssh Openbsd 3.2.3p1 (including) 3.2.3p1 (including)
Openssh Openbsd 3.3 (including) 3.3 (including)
Openssh Openbsd 3.3p1 (including) 3.3p1 (including)

References