CVE-2013-4208
Summary
| CVE | CVE-2013-4208 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-08-19 23:55:08 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The rsa_verify function in PuTTY before 0.63 (1) does not clear sensitive process memory after use and (2) does not free certain structures containing sensitive process memory, which might allow local users to discover private RSA and DSA keys. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Putty | Putty | 0.45 | All | All | All |
| Application | Putty | Putty | 0.46 | All | All | All |
| Application | Putty | Putty | 0.47 | All | All | All |
| Application | Putty | Putty | 0.48 | All | All | All |
| Application | Putty | Putty | 0.49 | All | All | All |
| Application | Putty | Putty | 0.50 | All | All | All |
| Application | Putty | Putty | 0.51 | All | All | All |
| Application | Putty | Putty | 0.52 | All | All | All |
| Application | Putty | Putty | 0.53b | All | All | All |
| Application | Putty | Putty | 0.54 | All | All | All |
| Application | Putty | Putty | 0.55 | All | All | All |
| Application | Putty | Putty | 0.56 | All | All | All |
| Application | Putty | Putty | 0.57 | All | All | All |
| Application | Putty | Putty | 0.58 | All | All | All |
| Application | Putty | Putty | 0.59 | All | All | All |
| Application | Putty | Putty | 0.60 | All | All | All |
| Application | Putty | Putty | 0.61 | All | All | All |
| Application | Simon Tatham | Putty | 0.53 | All | All | All |
| Application | Simon Tatham | Putty | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PuTTY vulnerability private-key-not-wiped | af854a3a-2127-422b-91ae-364da2661108 | www.chiark.greenend.org.uk | |
| openSUSE-SU-2013:1347-1: moderate: filezilla: 3.7.3 version and security | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Security Advisory SA54379 - Debian update for putty - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| oss-security - CVE request: three additional flaws fixed in putty 0.63 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Debian -- Security Information -- DSA-2736-1 putty | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.