CVE-2002-1644: SSH SSH2

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid to remove the child process from the process group of the parent process, which allows attackers to gain certain privileges.

Affected products

  • SSH SSH2: version 2.0.13 only; version 2.1 only; version 2.2 only; version 2.3 only; version 2.4 only; version 2.5 only; …

Published 2002-11-25. Last modified 2026-06-16.