MidnightBSD

Advisories for netcomposite

CVE-2002-1357 HIGH

Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
putty putty 0.49
cisco ios 12.2
cisco ios 12.2s
cisco ios 12.0s
netcomposite shellguard_ssh 3.4.6
fissh ssh_client 1.0a_for_windows
putty putty 0.53
cisco ios 12.2t
intersoft securenetterm 5.4.1
winscp winscp 2.0.0
cisco ios 12.0st
cisco ios 12.1ea
cisco ios 12.1e
putty putty 0.48
pragma_systems secureshell 2.0
cisco ios 12.1t
CVE-2002-1358 HIGH

Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
putty putty 0.49
cisco ios 12.2
cisco ios 12.2s
cisco ios 12.0s
netcomposite shellguard_ssh 3.4.6
fissh ssh_client 1.0a_for_windows
putty putty 0.53
cisco ios 12.2t
intersoft securenetterm 5.4.1
winscp winscp 2.0.0
cisco ios 12.0st
cisco ios 12.1ea
cisco ios 12.1e
putty putty 0.48
pragma_systems secureshell 2.0
cisco ios 12.1t
CVE-2002-1359 HIGH

Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
putty putty 0.49
cisco ios 12.2
cisco ios 12.2s
cisco ios 12.0s
netcomposite shellguard_ssh 3.4.6
fissh ssh_client 1.0a_for_windows
putty putty 0.53
cisco ios 12.2t
intersoft securenetterm 5.4.1
winscp winscp 2.0.0
cisco ios 12.0st
cisco ios 12.1ea
cisco ios 12.1e
putty putty 0.48
pragma_systems secureshell 2.0
cisco ios 12.1t
CVE-2002-1360 HIGH

Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as implemented using languages such as C, as demonstrated by the SSHredder SSH protocol test suite.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
putty putty 0.49
cisco ios 12.2
cisco ios 12.2s
cisco ios 12.0s
netcomposite shellguard_ssh 3.4.6
fissh ssh_client 1.0a_for_windows
putty putty 0.53
cisco ios 12.2t
intersoft securenetterm 5.4.1
winscp winscp 2.0.0
cisco ios 12.0st
cisco ios 12.1ea
cisco ios 12.1e
putty putty 0.48
pragma_systems secureshell 2.0
cisco ios 12.1t