cbcvebase.
CVE-2006-7162
published 2007-03-07

CVE-2006-7162: PuTTY 0.59 and earlier uses weak file permissions for (1) ppk files containing private keys generated by puttygen and (2) session logs created by putty, which…

PriorityP45low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.30%
22.0th percentile
PuTTY 0.59 and earlier uses weak file permissions for (1) ppk files containing private keys generated by puttygen and (2) session logs created by putty, which allows local users to gain sensitive information by reading these files.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianputty< putty 0.59-1 (bookworm)putty 0.59-1 (bookworm)
puttyputty<= 0.59
puttyputty>= 0 < 0.59-10.59-1
puttyputty>= 0 < 0.59-10.59-1
puttyputty>= 0 < 0.59-10.59-1
puttyputty>= 0 < 0.59-10.59-1

CVSS provenance

nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv1.9LOW
vendor_debian1.9LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.