Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication
Published Apr 2, 2003
9.8
CRITICALCVSS 3.1
EPSS 18.29%
Description
Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication.
Affected products
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of OpenSSH as shipped with Red Hat Enterprise Linux 3 or later. This issue did not affect the OpenSSL packages as shipped with Red Hat Enterprise Linux 2.1 as they were not compiled with S/Key or BSD_AUTH support. The upstream patch for this issue and CVE-2002-0640 was included in an errata so that users recompiling OpenSSL with support for those authentication methods would also be protected: https://rhn.redhat.com/errata/RHSA-2002-131.html
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (26 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 18.29% (0.18288) | 97.14th | v5 (v2026.06.15) |
| Jun 15, 2026 | 18.43% (0.18431) | 96.86th | v5 (v2026.06.15) |
| May 14, 2026 | 33.71% (0.33708) | 97.00th | v4 (v2025.03.14) |
| Apr 10, 2026 | 36.72% (0.36717) | 97.14th | v4 (v2025.03.14) |
| Mar 28, 2026 | 34.27% (0.34268) | 96.95th | v4 (v2025.03.14) |
| Mar 23, 2026 | 36.64% (0.36641) | 97.09th | v4 (v2025.03.14) |
| Mar 21, 2026 | 32.03% (0.32026) | 96.77th | v4 (v2025.03.14) |
| Mar 3, 2026 | 33.71% (0.33708) | 96.88th | v4 (v2025.03.14) |
| Feb 12, 2026 | 35.51% (0.35510) | 96.95th | v4 (v2025.03.14) |
| Jan 1, 2026 | 29.73% (0.29734) | 96.50th | v4 (v2025.03.14) |
| Dec 2, 2025 | 43.72% (0.43716) | 97.39th | v4 (v2025.03.14) |
| Sep 29, 2025 | 28.61% (0.28607) | 96.38th | v4 (v2025.03.14) |
| Apr 16, 2025 | 31.06% (0.31061) | 96.43th | v4 (v2025.03.14) |
| Mar 30, 2025 | 41.38% (0.41384) | 97.13th | v4 (v2025.03.14) |
| Mar 29, 2025 | 47.73% (0.47729) | 96.65th | v4 (v2025.03.14) |
| Mar 22, 2025 | 41.38% (0.41384) | 97.15th | v4 (v2025.03.14) |
| Mar 18, 2025 | 43.72% (0.43716) | 97.25th | v4 (v2025.03.14) |
| Mar 17, 2025 | 12.91% (0.12906) | 93.49th | v4 (v2025.03.14) |
| Dec 17, 2024 | 42.60% (0.42596) | 97.38th | v3 (v2023.03.01) |
| Feb 9, 2024 | 28.67% (0.28669) | 96.70th | v3 (v2023.03.01) |
| Feb 8, 2024 | 73.58% (0.73585) | 98.00th | v3 (v2023.03.01) |
| Jan 29, 2024 | 78.47% (0.78469) | 97.99th | v3 (v2023.03.01) |
| Mar 7, 2023 | 74.07% (0.74067) | 97.52th | v3 (v2023.03.01) |
| Mar 6, 2023 | 12.25% (0.12248) | 95.30th | v2 (v2022.01.01) |
| Apr 1, 2022 | 12.25% (0.12248) | 94.93th | v2 (v2022.01.01) |
| Feb 4, 2022 | 12.25% (0.12248) | 89.34th | v2 (v2022.01.01) |
References (20)
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-030.0.txt vendor-advisoryx_refsource_CALDERABroken Link
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0335.html mailing-listx_refsource_BUGTRAQBroken Link
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000502 vendor-advisoryx_refsource_CONECTIVABroken Link
- http://marc.info/?l=bugtraq&m=102514371522793&w=2 mailing-listx_refsource_BUGTRAQExploitMailing List
- http://marc.info/?l=bugtraq&m=102514631524575&w=2 mailing-listx_refsource_BUGTRAQExploitMailing List
- http://marc.info/?l=bugtraq&m=102521542826833&w=2 mailing-listx_refsource_BUGTRAQExploitMailing List
- http://www.cert.org/advisories/CA-2002-18.html third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- http://www.debian.org/security/2002/dsa-134 vendor-advisoryx_refsource_DEBIANBroken Link
- http://www.iss.net/security_center/static/9169.php vdb-entryx_refsource_XFBroken Link
- http://www.kb.cert.org/vuls/id/369347 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.linuxsecurity.com/advisories/other_advisory-2177.html vendor-advisoryx_refsource_ENGARDEBroken Link
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:040 vendor-advisoryx_refsource_MANDRAKEBroken Link
- http://www.osvdb.org/6245 vdb-entryx_refsource_OSVDBBroken Link
- http://www.securityfocus.com/bid/5093 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0206-195 vendor-advisoryx_refsource_HPBroken Link
- https://access.redhat.com/security/cve/CVE-2002-0639 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2002-0639
- https://twitter.com/RooneyMcNibNug/status/1152332585349111810 x_refsource_MISCBroken Link
- https://web.archive.org/web/20080622172542/www.iss.net/threats/advise123.html third-party-advisoryx_refsource_ISSThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2002-0639
Change history (0)
No recorded changes yet.