Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as implemented using languages such as C, as demonstrated by the SSHredder SSH protocol test suite.
Advisories
Source ID Title
EUVD EUVD EUVD-2002-1344 Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as implemented using languages such as C, as demonstrated by the SSHredder SSH protocol test suite.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-08T03:19:28.662Z

Reserved: 2002-12-14T00:00:00

Link: CVE-2002-1360

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2002-12-23T05:00:00.000

Modified: 2025-04-03T01:03:51.193

Link: CVE-2002-1360

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.