CVE-2002-0639: OpenBSD OpenSSH
Critical severity, CVSS 9.8. EPSS: 18.3% chance of exploitation in the next 30 days.
Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication.
Affected products
- OpenBSD OpenSSH: from 2.9.9, up to and including 3.3
Published 2002-07-03. Last modified 2026-06-16.