suse · CVE-2002-0640

Quick triage

Priority: critical Published: 2024-07-02 02:24:23 UTC Updated: 2024-07-05 02:46:19 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2002-0640 severity critical: SUSE including 8 source package names (openssh, openssh-askpass-gnome, …), 223 product×package rows across 46 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 7.1, … (46 product lines)): Known Not Affected 223.

Description:

Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses during challenge response authentication when OpenBSD is using PAM modules with interactive keyboard authentication (PAMAuthenticationViaKbdInt).

cvelogic Threat Intelligence