PT-2003-1333 · Simon Tatham · Putty
Knud Erik Højgaard
·
Published
2003-02-01
·
Updated
2016-10-18
·
CVE-2003-0048
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PuTTY versions 0.53b and earlier
Description
The issue concerns the storage of logon credentials in memory. Specifically, it does not clear credentials, including plaintext passwords, from memory, which could allow attackers with access to memory to steal the SSH credentials.
Recommendations
For PuTTY versions 0.53b and earlier, update to a version that properly clears logon credentials from memory to prevent potential theft of SSH credentials.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Putty