CVE-2003-0048
published 2003-02-19CVE-2003-0048: PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal…
PriorityP49medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.38%
30.7th percentile
PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | putty | < putty 0.53-b-2003-01-04-1 (bookworm) | putty 0.53-b-2003-01-04-1 (bookworm) |
| putty | putty | — | — |
| putty | putty | — | — |
| putty | putty | — | — |
| putty | putty | — | — |
| putty | putty | >= 0 < 0.53-b-2003-01-04-1 | 0.53-b-2003-01-04-1 |
| putty | putty | >= 0 < 0.53-b-2003-01-04-1 | 0.53-b-2003-01-04-1 |
| putty | putty | >= 0 < 0.53-b-2003-01-04-1 | 0.53-b-2003-01-04-1 |
| putty | putty | >= 0 < 0.53-b-2003-01-04-1 | 0.53-b-2003-01-04-1 |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vqgf-8h52-rhrp: PuTTY 0
ghsa_unreviewed·2022-04-29
CVE-2003-0048 [MEDIUM] GHSA-vqgf-8h52-rhrp: PuTTY 0
PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.
OSV
CVE-2003-0048: PuTTY 0
osv·2003-02-19·CVSS 4.6
CVE-2003-0048 [MEDIUM] CVE-2003-0048: PuTTY 0
PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.
Debian
CVE-2003-0048: putty - PuTTY 0.53b and earlier does not clear logon credentials from memory, including ...
vendor_debian·2003·CVSS 4.6
CVE-2003-0048 [MEDIUM] CVE-2003-0048: putty - PuTTY 0.53b and earlier does not clear logon credentials from memory, including ...
PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.
Scope: local
bookworm: resolved (fixed in 0.53-b-2003-01-04-1)
bullseye: resolved (fixed in 0.53-b-2003-01-04-1)
forky: resolved (fixed in 0.53-b-2003-01-04-1)
sid: resolved (fixed in 0.53-b-2003-01-04-1)
trixie: resolved (fixed in 0.53-b-2003-01-04-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=104386492422014&w=2http://www.idefense.com/advisory/01.28.03.txthttp://www.securityfocus.com/bid/6724http://www.securitytracker.com/id?1006014http://marc.info/?l=bugtraq&m=104386492422014&w=2http://www.idefense.com/advisory/01.28.03.txthttp://www.securityfocus.com/bid/6724http://www.securitytracker.com/id?1006014
2003-02-19
Published