PT-2007-1440 · Simon Tatham · Putty
Daniel Kahn Gillmor
·
Published
2007-03-07
·
Updated
2008-09-05
·
CVE-2006-7162
CVSS v2.0
1.9
Low
| Vector | AV:L/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PuTTY versions 0.59 and earlier
Description
The issue allows local users to gain sensitive information by reading certain files due to weak file permissions. This affects (1) ppk files containing private keys generated by puttygen and (2) session logs created by putty.
Recommendations
For PuTTY versions 0.59 and earlier, consider changing the file permissions of ppk files and session logs to restrict access and prevent unauthorized reading of sensitive information. As a temporary workaround, restrict access to the puttygen and putty applications until a fix is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Putty