← Back

CVE-2002-1360

nvd nist
Published: Dec 23, 2002Modified: Apr 16, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as implemented using languages such as C, as demonstrated by the SSHredder SSH protocol test suite.

Affected (16)

Products: Cisco: Ios · Fissh: Ssh Client · Intersoft: Securenetterm · +4 more
Show all products
1 product
Ios
1 product
Ssh Client
1 product
Securenetterm
1 product
Shellguard Ssh
Secureshell
1 product
Putty
1 product
Winscp
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 12.0s
Version 12.0st
Version 12.1e
Version 12.1ea
Version 12.1t
Version 12.2
Version 12.2s
Version 12.2t
Version 1.0a_for_windows
Version 5.4.1
Version 3.4.6
Version 2.0
Putty
Version 0.48
Version 0.49
Version 0.53
Version 2.0.0

References (10)

Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.