CVE-2013-4852
Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a denial of service (crash) and possibly execute arbitrary code in certain applications that use PuTTY via a negative…
Does this matter?
Lower severity and a low EPSS score (3.45%). Track it; it rarely justifies an emergency change on its own.
Description
Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a denial of service (crash) and possibly execute arbitrary code in certain applications that use PuTTY via a negative size value in an RSA key signature during the SSH handshake, which triggers a heap-based buffer overflow.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 3.45% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- winscp/winscp · debian/debian linux · opensuse/opensuse · putty/putty · simon tatham/putty
- Source
- cve@mitre.org
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=718779
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00035.html
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00041.html
- http://secunia.com/advisories/54379Vendor Advisory
- http://secunia.com/advisories/54517
- http://secunia.com/advisories/54533
- http://svn.tartarus.org/sgt?view=revision&sortby=date&revision=9896
- http://winscp.net/tracker/show_bug.cgi?id=1017
- http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-signature-stringlen.htmlVendor Advisory
- http://www.debian.org/security/2013/dsa-2736
- http://www.search-lab.hu/advisories/secadv-20130722
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=718779
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00035.html
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00041.html
- http://secunia.com/advisories/54379Vendor Advisory
- http://secunia.com/advisories/54517
- http://secunia.com/advisories/54533
- http://svn.tartarus.org/sgt?view=revision&sortby=date&revision=9896
- http://winscp.net/tracker/show_bug.cgi?id=1017
- http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-signature-stringlen.htmlVendor Advisory
- http://www.debian.org/security/2013/dsa-2736
- http://www.search-lab.hu/advisories/secadv-20130722
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.