PT-2007-1440 · Simon Tatham · Putty

Daniel Kahn Gillmor

·

Published

2007-03-07

·

Updated

2008-09-05

·

CVE-2006-7162

CVSS v2.0

1.9

Low

VectorAV:L/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PuTTY versions 0.59 and earlier
Description The issue allows local users to gain sensitive information by reading certain files due to weak file permissions. This affects (1) ppk files containing private keys generated by puttygen and (2) session logs created by putty.
Recommendations For PuTTY versions 0.59 and earlier, consider changing the file permissions of ppk files and session logs to restrict access and prevent unauthorized reading of sensitive information. As a temporary workaround, restrict access to the puttygen and putty applications until a fix is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-7162

Affected Products

Putty