CVE-2002-1059: Buffer Overflow
Published Oct 4, 2002
·Updated
Buffer overflow in Van Dyke SecureCRT SSH client before 3.4.6, and 4.x before 4.0 beta 3, allows an SSH server to execute arbitrary code via a long SSH1 protocol version string.
Affected Software
19 affected components
Van Dyke Technologies Securecrt=3.2.1
Van Dyke Technologies Securecrt=3.4.5
Van Dyke Technologies Securecrt=4.0_beta_2
Van Dyke Technologies Securecrt=3.4.4
Van Dyke Technologies Securecrt=3.3.2
Van Dyke Technologies Securecrt=3.4.1
Van Dyke Technologies Securecrt=3.4
Van Dyke Technologies Securecrt=3.4.3
Van Dyke Technologies Securecrt=3.0
Van Dyke Technologies Securecrt=2.4
Van Dyke Technologies Securecrt=3.1
Van Dyke Technologies Securecrt=3.3.3
Van Dyke Technologies Securecrt=3.1.2
Van Dyke Technologies Securecrt=3.3.1
Van Dyke Technologies Securecrt=4.0_beta_1
Van Dyke Technologies Securecrt=3.1.1
Van Dyke Technologies Securecrt=3.3
Van Dyke Technologies Securecrt=3.4.2
Van Dyke Technologies Securecrt=3.2
Remediation
Patch Available
Patch Available
Event History
Oct 4, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1059?
CVE-2002-1059 is classified as a critical vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2002-1059?
To resolve CVE-2002-1059, upgrade to SecureCRT version 3.4.6 or later, or 4.x version 4.0 beta 3 or later.
3
What versions of SecureCRT are affected by CVE-2002-1059?
CVE-2002-1059 affects SecureCRT versions prior to 3.4.6 and 4.x versions before 4.0 beta 3.
4
What type of attack does CVE-2002-1059 enable?
CVE-2002-1059 enables unauthorized execution of arbitrary code through a buffer overflow vulnerability.
5
Who is impacted by CVE-2002-1059?
Users of affected SecureCRT versions are at risk of exploitation due to CVE-2002-1059.