CVE-2002-1645: Buffer Overflow
Published Nov 25, 2002
·Updated
Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbitrary code via a long URL.
Affected Software
6 affected components
SSH Ssh2=3.1
SSH Ssh2=3.1.1
SSH Ssh2=3.1.2
SSH Ssh2=3.1.3
SSH Ssh2=3.1.4
SSH Ssh2=3.2
Remediation
Patch Available
Patch Available
Patch Available
Event History
Nov 25, 2002
CVE Published
05:00 AM
Mar 28, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1645?
CVE-2002-1645 is considered a high severity vulnerability due to the buffer overflow that allows remote code execution.
2
How do I fix CVE-2002-1645?
To fix CVE-2002-1645, upgrade your SSH Secure Shell for Workstations client to version 3.2 or later.
3
Which versions of SSH are affected by CVE-2002-1645?
CVE-2002-1645 affects SSH Secure Shell for Workstations client versions 3.1 to 3.2.0.
4
What type of attack can CVE-2002-1645 facilitate?
CVE-2002-1645 can facilitate remote code execution attacks via a long URL input.
5
Is CVE-2002-1645 a known vulnerability?
Yes, CVE-2002-1645 is a well-documented vulnerability first reported in 2002.