First published: Tue Dec 31 2002(Updated: )
SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to a world-writeable directory, then executing that script to gain normal shell access.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SSH (Secure Shell) | =1.2.6 | |
SSH (Secure Shell) | =1.2.0 | |
SSH (Secure Shell) | =2.0.13 | |
SSH (Secure Shell) | =2.1 | |
SSH (Secure Shell) | =2.0.3 | |
SSH (Secure Shell) | =2.0.8 | |
SSH (Secure Shell) | =1.2.9 | |
SSH (Secure Shell) | =1.2.21 | |
SSH (Secure Shell) | =1.2.15 | |
SSH (Secure Shell) | =2.0.11 | |
SSH (Secure Shell) | =2.0.9 | |
SSH (Secure Shell) | =2.2 | |
SSH (Secure Shell) | =1.2.4 | |
SSH (Secure Shell) | =1.2.14 | |
SSH (Secure Shell) | =1.2.19 | |
SSH (Secure Shell) | =2.0 | |
SSH (Secure Shell) | =2.0.5 | |
SSH (Secure Shell) | =1.2.8 | |
SSH (Secure Shell) | =1.2.31 | |
SSH (Secure Shell) | =1.2.24 | |
SSH (Secure Shell) | =1.2.18 | |
SSH (Secure Shell) | =1.2.7 | |
SSH (Secure Shell) | =1.2.20 | |
SSH (Secure Shell) | =1.2.3 | |
SSH (Secure Shell) | =1.2.12 | |
SSH (Secure Shell) | =1.2.25 | |
SSH (Secure Shell) | =1.2.17 | |
SSH (Secure Shell) | =2.0.6 | |
SSH (Secure Shell) | =3.0 | |
SSH (Secure Shell) | =2.0.4 | |
SSH (Secure Shell) | =1.2.30 | |
SSH (Secure Shell) | =1.2.1 | |
SSH (Secure Shell) | =1.2.26 | |
SSH (Secure Shell) | =1.2.27 | |
SSH (Secure Shell) | =1.2.16 | |
SSH (Secure Shell) | =2.4 | |
SSH (Secure Shell) | =1.2.28 | |
SSH (Secure Shell) | =2.0.1 | |
SSH (Secure Shell) | =1.2.29 | |
SSH (Secure Shell) | =1.2.11 | |
SSH (Secure Shell) | =1.2.5 | |
SSH (Secure Shell) | =2.0.10 | |
SSH (Secure Shell) | =1.2.13 | |
SSH (Secure Shell) | =1.2.22 | |
SSH (Secure Shell) | =1.2.2 | |
SSH (Secure Shell) | =2.3 | |
SSH (Secure Shell) | =1.2.23 | |
SSH (Secure Shell) | =2.5 | |
SSH (Secure Shell) | =2.0.12 | |
SSH (Secure Shell) | =1.2.10 | |
SSH (Secure Shell) | =2.0.7 | |
SSH (Secure Shell) | =2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1715 has a medium severity rating due to its potential to allow unauthorized shell access.
To fix CVE-2002-1715, restrict write permissions on directories to prevent script uploads and ensure proper configuration of user shells.
CVE-2002-1715 affects SSH versions 1 through 3, including specific versions like 1.2.0 and 2.0.13.
The main impact of CVE-2002-1715 is that it allows local users to bypass restricted shell environments, gaining unrestricted access.
Local users who have access to a vulnerable SSH application may exploit CVE-2002-1715 to gain unauthorized shell access.