CyberSec.Space Logo
返回 CVE 浏览器

CVE-2002-1360

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0520%
EPSS Percentile40.34th
Published2002年12月23日
Last Modified2026年4月16日

Vulnerability Description

Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as implemented using languages such as C, as demonstrated by the SSHredder SSH protocol test suite.

Affected Platforms (CPE)

💻
Cisco

Ios

= 12.0s
💻
Cisco

Ios

= 12.0st
💻
Cisco

Ios

= 12.1e
💻
Cisco

Ios

= 12.1ea
💻
Cisco

Ios

= 12.1t
💻
Cisco

Ios

= 12.2
💻
Cisco

Ios

= 12.2s
💻
Cisco

Ios

= 12.2t
📦
Fissh

Ssh Client

= 1.0a_for_windows
📦
Intersoft

Securenetterm

= 5.4.1
📦
Netcomposite

Shellguard Ssh

= 3.4.6
📦
Pragma Systems

Secureshell

= 2.0
📦
Putty

Putty

= 0.48
📦
Putty

Putty

= 0.49
📦
Putty

Putty

= 0.53
📦
Winscp

Winscp

= 2.0.0

References & Advisories

相关漏洞威胁