CVE-2013-4208
Last modified
CVE-2013-4208 is a vulnerability of currently unknown severity. The rsa_verify function in PuTTY before 0.63 (1) does not clear sensitive process memory after use and (2) does not free certain structures containing sensitive process memory, which might allow local users to discover private RSA and DSA keys.. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
The rsa_verify function in PuTTY before 0.63 (1) does not clear sensitive process memory after use and (2) does not free certain structures containing sensitive process memory, which might allow local users to discover private RSA and DSA keys.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Putty | Putty | 0.45 |
| Putty | Putty | 0.46 |
| Putty | Putty | 0.47 |
| Putty | Putty | 0.48 |
| Putty | Putty | 0.49 |
| Putty | Putty | 0.50 |
| Putty | Putty | 0.51 |
| Putty | Putty | 0.52 |
| Putty | Putty | 0.53b |
| Putty | Putty | 0.54 |
| Putty | Putty | 0.55 |
| Putty | Putty | 0.56 |
| Putty | Putty | 0.57 |
| Putty | Putty | 0.58 |
| Putty | Putty | 0.59 |
| Putty | Putty | 0.60 |
| Putty | Putty | 0.61 |
| Simon Tatham | Putty | <= 0.62 |
| Simon Tatham | Putty | 0.53 |
References
- http://secunia.com/advisories/54379Vendor Advisory
- http://secunia.com/advisories/54379Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-4208?
How severe is CVE-2013-4208?
How do I fix CVE-2013-4208?
Are you affected by CVE-2013-4208?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
