PT-2016-5210 · Simon Tatham+2 · Putty+2

Tintinweb

·

Published

2016-03-05

·

Updated

2016-12-03

·

CVE-2016-2563

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PuTTY versions prior to 0.67 KiTTY versions prior to 0.66.6.3
Description A stack-based buffer overflow issue exists in the SCP command-line utility, allowing remote servers to cause a denial of service or execute arbitrary code via a crafted SCP-SINK file-size response to an SCP download request.
Recommendations For PuTTY versions prior to 0.67, update to version 0.67 or later to resolve the issue. For KiTTY versions prior to 0.66.6.3, update to version 0.66.6.3 or later to resolve the issue.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1194
CVE-2016-2563
MGASA-2016-0112
MGASA-2016-0118

Affected Products

Alt Linux
Kitty
Putty