CVE-2002-0083: Critical severity Immunix Immunix vulnerability
Published Mar 15, 2002
·Updated
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
Affected Software
50 affected components
Immunix Immunix=7.0
Mandrakesoft Mandrake Single Network Firewall=7.2
OpenBSD OpenSSH>=2.0<3.1
Openpkg Openpkg=1.0
Conectiva Linux=5.0
Conectiva Linux=5.1
Conectiva Linux=6.0
Conectiva Linux=7.0
Conectiva Linux=ecommerce
Conectiva Linux=graficas
Engardelinux Secure Linux=1.0.1
Mandrakesoft Mandrake Linux=7.1
Mandrakesoft Mandrake Linux=7.2
Mandrakesoft Mandrake Linux=8.0
Mandrakesoft Mandrake Linux=8.0
Mandrakesoft Mandrake Linux=8.1
Mandrakesoft Mandrake Linux Corporate Server=1.0.1
redhat Linux=7.0
redhat Linux=7.1
redhat Linux=7.2
SUSE SuSE Linux=6.4
SUSE SuSE Linux=6.4
SUSE SuSE Linux=6.4-alpha
SUSE SuSE Linux=7.0
SUSE SuSE Linux=7.0
SUSE SuSE Linux=7.0
SUSE SuSE Linux=7.0-alpha
SUSE SuSE Linux=7.1
SUSE SuSE Linux=7.1
SUSE SuSE Linux=7.1
SUSE SuSE Linux=7.1-alpha
SUSE SuSE Linux=7.2
SUSE SuSE Linux=7.3
SUSE SuSE Linux=7.3
SUSE SuSE Linux=7.3
Trustix Secure Linux=1.1
Trustix Secure Linux=1.2
Trustix Secure Linux=1.5
OpenBSD OpenSSH=2.1
OpenBSD OpenSSH=2.1.1
OpenBSD OpenSSH=2.2
OpenBSD OpenSSH=2.3
OpenBSD OpenSSH=2.5
OpenBSD OpenSSH=2.5.1
OpenBSD OpenSSH=2.5.2
OpenBSD OpenSSH=2.9
OpenBSD OpenSSH=2.9.9
OpenBSD OpenSSH=2.9p1
OpenBSD OpenSSH=2.9p2
OpenBSD OpenSSH=3.0.1
Remediation
Patch Available
Event History
Mar 15, 2002
CVE Published
via NVD·05:00 AM
Jun 25, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0083?
CVE-2002-0083 has been classified as a critical vulnerability that allows local users or remote malicious servers to gain elevated privileges.
2
How do I fix CVE-2002-0083?
To fix CVE-2002-0083, upgrade to OpenSSH version 3.1 or later, or apply patches provided by your distribution vendor.
3
Which versions of OpenSSH are affected by CVE-2002-0083?
CVE-2002-0083 affects OpenSSH versions 2.0 through 3.0.2.
4
Can CVE-2002-0083 be exploited remotely?
Yes, CVE-2002-0083 can be exploited remotely if the vulnerable OpenSSH server is accessible over the network.
5
What types of systems are impacted by CVE-2002-0083?
CVE-2002-0083 impacts a variety of systems including those running Immunix, Mandrake, Conectiva Linux, Red Hat Linux, and SUSE Linux with the affected OpenSSH versions.