PuTTY Multiple Security Vulnerabilities
BID:107484
Info
PuTTY Multiple Security Vulnerabilities
| Bugtraq ID: | 107484 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 16 2019 12:00AM |
| Updated: | Mar 16 2019 12:00AM |
| Credit: | Unknown |
| Vulnerable: |
Simon Tatham PuTTY 0.58 Simon Tatham PuTTY 0.57 Simon Tatham PuTTY 0.56 Simon Tatham PuTTY 0.55 Simon Tatham PuTTY 0.54 Simon Tatham PuTTY 0.53 b Simon Tatham PuTTY 0.53 Simon Tatham PuTTY 0.52 Simon Tatham PuTTY 0.51 Simon Tatham PuTTY 0.50 Simon Tatham PuTTY 0.49 Simon Tatham PuTTY 0.48 Simon Tatham PuTTY 0.68 Simon Tatham PuTTY 0.66 Simon Tatham PuTTY 0.65 Simon Tatham PuTTY 0.64 Simon Tatham PuTTY 0.63 Simon Tatham PuTTY 0.62 Simon Tatham PuTTY 0.61 Simon Tatham PuTTY 0.60 Simon Tatham PuTTY 0.6 Simon Tatham PuTTY 0.59 Simon Tatham PuTTY 0.58 Simon Tatham PuTTY 0.57 Simon Tatham PuTTY 0.56 Simon Tatham PuTTY 0.55 Simon Tatham PuTTY 0.54 Simon Tatham PuTTY 0.53B Simon Tatham PuTTY 0.53 B Simon Tatham PuTTY 0.53 Simon Tatham PuTTY 0.52 Simon Tatham PuTTY 0.51 Simon Tatham PuTTY 0.50 Simon Tatham PuTTY 0.49 Simon Tatham PuTTY 0.48 Simon Tatham PuTTY 0.47 Simon Tatham PuTTY 0.46 Simon Tatham PuTTY 0.45 |
| Not Vulnerable: |
Simon Tatham PuTTY 0.71 |
Discussion
PuTTY Multiple Security Vulnerabilities
PuTTY is prone to the following vulnerabilities:
1. A memory-corruption vulnerability
2. An buffer-overflow vulnerability
3. Multiple denial of service vulnerabilities
4. A security bypass vulnerability
An attacker may leverage these issues to execute arbitrary code, cause a denial-of-service condition, perform unauthorized actions or gain access to sensitive information that may aid in further attacks.
Versions prior to PuTTY 0.71 is vulnerable; other versions may also be affected.
PuTTY is prone to the following vulnerabilities:
1. A memory-corruption vulnerability
2. An buffer-overflow vulnerability
3. Multiple denial of service vulnerabilities
4. A security bypass vulnerability
An attacker may leverage these issues to execute arbitrary code, cause a denial-of-service condition, perform unauthorized actions or gain access to sensitive information that may aid in further attacks.
Versions prior to PuTTY 0.71 is vulnerable; other versions may also be affected.
Exploit / POC
PuTTY Multiple Security Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
PuTTY Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
PuTTY Multiple Security Vulnerabilities
References:
References:
- Download PuTTY: latest release (0.71) (Putty)
- PuTTY 0.71 is released (tartarus.org)
- PuTTY Homepage (PuTTY Project)
- PuTTY in your hands: SSH client gets patched after RSA key exchange memory vuln (theregister.co.uk)