cbcvebase.
CVE-2004-1440
published 2004-12-31

CVE-2004-1440: Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via an SSH2 packet with a…

PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.11%
89.7th percentile
Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via an SSH2 packet with a base argument that is larger than the mod argument, which causes the modpow function to write memory before the beginning of its buffer, and (2) remote malicious servers to cause a denial of service (client crash) and possibly execute arbitrary code via a large bignum during authentication.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianputty< putty 0.56-1 (bookworm)putty 0.56-1 (bookworm)
puttyputty
puttyputty
puttyputty
puttyputty
puttyputty
puttyputty
puttyputty
puttyputty
puttyputty>= 0 < 0.56-10.56-1
puttyputty>= 0 < 0.56-10.56-1
puttyputty>= 0 < 0.56-10.56-1
puttyputty>= 0 < 0.56-10.56-1

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.