PuTTY CVE-2015-2157 Local Information Disclosure Vulnerability
BID:72825
Info
PuTTY CVE-2015-2157 Local Information Disclosure Vulnerability
| Bugtraq ID: | 72825 |
| Class: | Design Error |
| CVE: |
CVE-2015-2157 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 28 2015 12:00AM |
| Updated: | May 07 2015 06:13PM |
| Credit: | Patrick Coleman |
| Vulnerable: |
Simon Tatham PuTTY 0.61 Simon Tatham PuTTY 0.60 Simon Tatham PuTTY 0.59 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
PuTTY CVE-2015-2157 Local Information Disclosure Vulnerability
PuTTY is prone to a local information-disclosure vulnerability.
Successful exploits will allow attackers with access to process memory to obtain potentially sensitive information. Information obtained may lead to further attacks.
PuTTY is prone to a local information-disclosure vulnerability.
Successful exploits will allow attackers with access to process memory to obtain potentially sensitive information. Information obtained may lead to further attacks.
Exploit / POC
PuTTY CVE-2015-2157 Local Information Disclosure Vulnerability
Local attackers can use standard tools to exploit this issue.
Local attackers can use standard tools to exploit this issue.
Solution / Fix
PuTTY CVE-2015-2157 Local Information Disclosure Vulnerability
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
References
PuTTY CVE-2015-2157 Local Information Disclosure Vulnerability
References:
References:
- PuTTY Changelogs (PuTTY Project)