Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2002-0083

CWE-1937 documents7 sources
Severity
9.8CRITICAL
EPSS
1.5%
top 18.70%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMar 15
Latest updateMay 3

Description

Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages11 packages

NVDopenbsd/openssh2.03.1
NVDredhat/linux7.0, 7.1, 7.2+2
NVDconectiva/linux6 versions+5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-w9fg-77jf-ghf9: Off-by-one error in the channel code of OpenSSH 22022-05-03
CVEList
CVE-2002-0083: Off-by-one error in the channel code of OpenSSH 22002-06-25

💥Exploits & PoCs

1
Exploit-DB
OpenSSH 2.x/3.0.1/3.0.2 - Channel Code Off-by-One2002-03-07

📋Vendor Advisories

1
Red Hat
security flaw2002-03-07

💬Community

1
Bugzilla
CVE-2002-0083 security flaw2018-08-16