CVE-2002-0083
published 2002-03-15CVE-2002-0083: Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
PriorityP346critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
14.80%
96.3th percentile
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| conectiva | linux | — | — |
| conectiva | linux | — | — |
| conectiva | linux | — | — |
| conectiva | linux | — | — |
| conectiva | linux | — | — |
| conectiva | linux | — | — |
| engardelinux | secure_linux | — | — |
| immunix | immunix | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux_corporate_server | — | — |
| mandrakesoft | mandrake_single_network_firewall | — | — |
| openbsd | openssh | >= 2.0 < 3.1 | 3.1 |
| openpkg | openpkg | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| trustix | secure_linux | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2002-03-07·CVSS 9.8
CVE-2002-0083 [CRITICAL] security flaw
security flaw
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
GHSA
GHSA-w9fg-77jf-ghf9: Off-by-one error in the channel code of OpenSSH 2
ghsa_unreviewed·2022-05-03
CVE-2002-0083 [HIGH] GHSA-w9fg-77jf-ghf9: Off-by-one error in the channel code of OpenSSH 2
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
No detection rules found.
Bugzilla
CVE-2002-0083 security flaw
bugzilla·2018-08-16·CVSS 9.8
CVE-2002-0083 [CRITICAL] CVE-2002-0083 security flaw
CVE-2002-0083 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
arXiv
ZeroDayBench: Evaluating LLM Agents on Unseen Zero-Day Vulnerabilities for Cyberdefense
arxiv_fulltext·2026-03-02
ZeroDayBench: Evaluating LLM Agents on Unseen Zero-Day Vulnerabilities for Cyberdefense
## Abstract
Large language models (LLMs) are increasingly being deployed as software engineering agents that autonomously contribute to repositories. A major benefit these agents present is their ability to find and patch security vulnerabilities in the codebases they oversee. To estimate the capability of agents in this domain, we introduce ZeroDayBench, a benchmark where LLM agents find and patch 22 novel critical vulnerabilities in open-source codebases. We focus our efforts on three popular frontier agentic LLMs: GPT-5.2, Claude Sonnet 4.5, and Grok 4.1. We find that frontier LLMs are not yet capable of autonomously solving our tasks and observe some behavioral patterns that suggest how these models can be improved in the domain of proactive cyberdefense.
## Introduction
Large langu
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:13.openssh.ascftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-004.txt.ascftp://stage.caldera.com/pub/security/openserver/CSSA-2002-SCO.10/CSSA-2002-SCO.10.txtftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.11/CSSA-2002-SCO.11.txthttp://archives.neohapsis.com/archives/bugtraq/2002-03/0108.htmlhttp://archives.neohapsis.com/archives/vulnwatch/2002-q1/0060.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000467http://marc.info/?l=bugtraq&m=101552065005254&w=2http://marc.info/?l=bugtraq&m=101553908201861&w=2http://marc.info/?l=bugtraq&m=101561384821761&w=2http://marc.info/?l=bugtraq&m=101586991827622&w=2http://online.securityfocus.com/advisories/3960http://online.securityfocus.com/archive/1/264657http://www.calderasystems.com/support/security/advisories/CSSA-2002-012.0.txthttp://www.debian.org/security/2002/dsa-119http://www.iss.net/security_center/static/8383.phphttp://www.linux-mandrake.com/en/security/2002/MDKSA-2002-019.phphttp://www.linuxsecurity.com/advisories/other_advisory-1937.htmlhttp://www.novell.com/linux/security/advisories/2002_009_openssh_txt.htmlhttp://www.openbsd.org/advisories/ssh_channelalloc.txthttp://www.osvdb.org/730http://www.redhat.com/support/errata/RHSA-2002-043.htmlhttp://www.securityfocus.com/bid/4241ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:13.openssh.ascftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-004.txt.ascftp://stage.caldera.com/pub/security/openserver/CSSA-2002-SCO.10/CSSA-2002-SCO.10.txtftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.11/CSSA-2002-SCO.11.txthttp://archives.neohapsis.com/archives/bugtraq/2002-03/0108.htmlhttp://archives.neohapsis.com/archives/vulnwatch/2002-q1/0060.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000467http://marc.info/?l=bugtraq&m=101552065005254&w=2http://marc.info/?l=bugtraq&m=101553908201861&w=2http://marc.info/?l=bugtraq&m=101561384821761&w=2http://marc.info/?l=bugtraq&m=101586991827622&w=2http://online.securityfocus.com/advisories/3960http://online.securityfocus.com/archive/1/264657http://www.calderasystems.com/support/security/advisories/CSSA-2002-012.0.txthttp://www.debian.org/security/2002/dsa-119http://www.iss.net/security_center/static/8383.phphttp://www.linux-mandrake.com/en/security/2002/MDKSA-2002-019.phphttp://www.linuxsecurity.com/advisories/other_advisory-1937.htmlhttp://www.novell.com/linux/security/advisories/2002_009_openssh_txt.htmlhttp://www.openbsd.org/advisories/ssh_channelalloc.txthttp://www.osvdb.org/730http://www.redhat.com/support/errata/RHSA-2002-043.htmlhttp://www.securityfocus.com/bid/4241
2002-03-15
Published