SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-4208

The rsa_verify function in PuTTY before 0.63 (1) does not clear sensitive process memory after use and (2) does not free certain structures containing sensitive process memory, which might allow local users to discover private RSA and DSA keys.

LOW 2.1EPSS 0.39%

Does this matter?

Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.

Description

The rsa_verify function in PuTTY before 0.63 (1) does not clear sensitive process memory after use and (2) does not free certain structures containing sensitive process memory, which might allow local users to discover private RSA and DSA keys.

CVSS 2.0
2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
EPSS
0.39% probability · 33th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
putty/putty · simon tatham/putty
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.