PT-2021-4283 · Putty+1 · Putty+1

Published

2021-05-21

·

Updated

2023-08-15

·

CVE-2021-33500

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PuTTY versions prior to 0.75
Description The issue allows remote servers to cause a denial of service by repeatedly changing the PuTTY window title at high speed, resulting in many SetWindowTextA or SetWindowTextW calls. This can cause the Windows GUI to hang. The same attack methodology may also affect some OS-level GUIs on Linux or other platforms.
Recommendations For versions prior to 0.75, update to version 0.75 or later to resolve the issue. As a temporary workaround, consider restricting access to the PuTTY window title change functionality to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4867
BDU:2021-04891
CVE-2021-33500

Affected Products

Alt Linux
Putty