CVE-2002-1358
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD
Description
Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
Affected (16)
Show all products
Cisco: Ios · Fissh: Ssh Client · Intersoft: Securenetterm · Netcomposite: Shellguard Ssh · Pragma Systems: Secureshell · Putty: Putty · Winscp: Winscp
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.0s | |
| Version 1.0a_for_windows | |
| Version 5.4.1 | |
| Version 3.4.6 | |
| Version 2.0 | |
| Version 0.48 | |
| Version 2.0.0 |
References (10)
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.