cbcvebase.
CVE-2005-0467
published 2005-02-21

CVE-2005-0467: Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier…

PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.04%
89.5th percentile
Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that corrupt the heap after insufficient memory has been allocated.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianputty< putty 0.57-1 (bookworm)putty 0.57-1 (bookworm)
puttyputty<= 0.56
puttyputty>= 0 < 0.57-10.57-1
puttyputty>= 0 < 0.57-10.57-1
puttyputty>= 0 < 0.57-10.57-1
puttyputty>= 0 < 0.57-10.57-1

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.