CVE-2002-0765: High severity OpenBSD OpenSSH vulnerability
Published Aug 12, 2002
·Updated
sshd in OpenSSH 3.2.2, when using YP with netgroups and under certain conditions, may allow users to successfully authenticate and log in with another user's password.
Affected Software
2 affected components
OpenBSD OpenSSH=3.2.2
OpenBSD OpenBSD=3.1
Remediation
Patch Available
Patch Available
Event History
Aug 12, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0765?
CVE-2002-0765 is considered a high severity vulnerability due to the potential for unauthorized access using another user's password.
2
How do I fix CVE-2002-0765?
To fix CVE-2002-0765, it is recommended to upgrade OpenSSH to a version beyond 3.2.2.
3
Which versions of OpenSSH are affected by CVE-2002-0765?
CVE-2002-0765 affects OpenSSH version 3.2.2 and earlier.
4
What conditions lead to the exploitation of CVE-2002-0765?
CVE-2002-0765 is exploited when using YP with netgroups under specific conditions allowing authentication with another user's password.
5
Are there any workarounds for CVE-2002-0765?
A workaround for CVE-2002-0765 may include disabling YP and netgroups in the SSH configuration.