PT-2019-5477 · Simon Tatham+1 · Putty+1
Publicado
2019-03-21
·
Atualizado
2019-05-07
·
CVE-2019-9895
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PuTTY versions prior to 0.71
Description
The issue is related to a buffer overflow in the cryptographic protection tool PuTTY, which can be triggered remotely. This can allow an attacker to impact the confidentiality, integrity, and availability of protected information. The buffer overflow exists in server-to-client forwarding on Unix systems.
Recommendations
For PuTTY versions prior to 0.71, update to version 0.71 or later to resolve the issue.
As a temporary workaround, consider restricting the use of server-to-client forwarding until a patch is available.
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Putty
Suse