{"api_version":"1","generated_at":"2026-07-23T06:04:50+00:00","cve":"CVE-2005-0467","urls":{"html":"https://cve.report/CVE-2005-0467","api":"https://cve.report/api/cve/CVE-2005-0467.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-0467","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-0467"},"summary":{"title":"CVE-2005-0467","description":"Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that corrupt the heap after insufficient memory has been allocated.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-02-21 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/17214","name":"http://secunia.com/advisories/17214","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - IBM TotalStorage SAN Volume Controller PuTTY Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002414","name":"http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002414","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"410"},{"url":"http://www.idefense.com/application/poi/display?id=201&type=vulnerabilities","name":"http://www.idefense.com/application/poi/display?id=201&type=vulnerabilities","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Accenture | Let there be change","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.gentoo.org/security/en/glsa/glsa-200502-28.xml","name":"http://www.gentoo.org/security/en/glsa/glsa-200502-28.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Gentoo Linux Documentation\n--\n  PuTTY: Remote code execution","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/14333","name":"http://secunia.com/advisories/14333","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - PuTTY Two Integer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-string.html","name":"http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-string.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"PuTTY vulnerability vuln-sftp-string","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-readdir.html","name":"http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-readdir.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"PuTTY vulnerability vuln-sftp-readdir","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002416","name":"http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002416","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"410"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19403","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19403","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-0467","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-0467","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"467","vulnerable":"1","versionEndIncluding":"0.56","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"putty","cpe5":"putty","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T21:13:54.249Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002414"},{"name":"putty-sftppktgetstring-bo(19403)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19403"},{"name":"20050221 Multiple PuTTY SFTP Client Packet Parsing Integer Overflow Vulnerabilities","tags":["third-party-advisory","x_refsource_IDEFENSE","x_transferred"],"url":"http://www.idefense.com/application/poi/display?id=201&type=vulnerabilities"},{"name":"14333","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/14333"},{"name":"GLSA-200502-28","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200502-28.xml"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002416"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-readdir.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-string.html"},{"name":"17214","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17214"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-02-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that corrupt the heap after insufficient memory has been allocated."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002414"},{"name":"putty-sftppktgetstring-bo(19403)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19403"},{"name":"20050221 Multiple PuTTY SFTP Client Packet Parsing Integer Overflow Vulnerabilities","tags":["third-party-advisory","x_refsource_IDEFENSE"],"url":"http://www.idefense.com/application/poi/display?id=201&type=vulnerabilities"},{"name":"14333","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/14333"},{"name":"GLSA-200502-28","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200502-28.xml"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002416"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-readdir.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-string.html"},{"name":"17214","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17214"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-0467","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that corrupt the heap after insufficient memory has been allocated."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002414","refsource":"CONFIRM","url":"http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002414"},{"name":"putty-sftppktgetstring-bo(19403)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19403"},{"name":"20050221 Multiple PuTTY SFTP Client Packet Parsing Integer Overflow Vulnerabilities","refsource":"IDEFENSE","url":"http://www.idefense.com/application/poi/display?id=201&type=vulnerabilities"},{"name":"14333","refsource":"SECUNIA","url":"http://secunia.com/advisories/14333"},{"name":"GLSA-200502-28","refsource":"GENTOO","url":"http://www.gentoo.org/security/en/glsa/glsa-200502-28.xml"},{"name":"http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002416","refsource":"CONFIRM","url":"http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002416"},{"name":"http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-readdir.html","refsource":"CONFIRM","url":"http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-readdir.html"},{"name":"http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-string.html","refsource":"CONFIRM","url":"http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-string.html"},{"name":"17214","refsource":"SECUNIA","url":"http://secunia.com/advisories/17214"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-0467","datePublished":"2005-02-21T05:00:00.000Z","dateReserved":"2005-02-18T00:00:00.000Z","dateUpdated":"2024-08-07T21:13:54.249Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-02-21 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:putty:putty:*:*:*:*:*:*:*:*","versionEndIncluding":"0.56","matchCriteriaId":"190CABAE-FF9C-44F5-9F8B-7E229DE6B67A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"467","Ordinal":"1","Title":"CVE-2005-0467","CVE":"CVE-2005-0467","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"467","Ordinal":"1","NoteData":"Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that corrupt the heap after insufficient memory has been allocated.","Type":"Description","Title":"CVE-2005-0467"},{"CveYear":"2005","CveId":"467","Ordinal":"2","NoteData":"2005-02-21","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"467","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}