CVE-2006-7162
Summary
| CVE | CVE-2006-7162 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-03-07 21:19:00 UTC |
| Updated | 2008-09-05 21:16:00 UTC |
| Description | PuTTY 0.59 and earlier uses weak file permissions for (1) ppk files containing private keys generated by puttygen and (2) session logs created by putty, which allows local users to gain sensitive information by reading these files. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| #400804 - putty-tools: puttygen can create world-readable private keys - Debian Bug report logs | CONFIRM | bugs.debian.org | Patch, Vendor Advisory |
| PuTTY "puttygen" Insecure File Permissions - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.