PT-2013-4899 · Simon Tatham · Putty
Published
2013-08-09
·
Updated
2024-06-15
·
CVE-2013-4208
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PuTTY versions prior to 0.63
Description
The issue concerns the rsa verify function, which does not properly clear sensitive process memory after use and fails to free certain structures containing sensitive process memory. This could potentially allow local users to discover private RSA and DSA keys.
Recommendations
For versions prior to 0.63, update to version 0.63 or later to resolve the issue.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Putty