cbcvebase.
CVE-2013-4207
published 2013-08-19

CVE-2013-4207: Buffer overflow in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (crash) via an invalid DSA signature that is not…

PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.83%
76.6th percentile
Buffer overflow in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (crash) via an invalid DSA signature that is not properly handled during computation of a modular inverse and triggers the overflow during a division by zero by the bignum functionality, a different vulnerability than CVE-2013-4206.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianfilezilla< filezilla 3.7.3-1 (bookworm)filezilla 3.7.3-1 (bookworm)
debianputty< filezilla 3.7.3-1 (bookworm)filezilla 3.7.3-1 (bookworm)
filezillafilezilla>= 0 < 3.7.3-13.7.3-1
filezillafilezilla>= 0 < 3.7.3-13.7.3-1
filezillafilezilla>= 0 < 3.7.3-13.7.3-1
filezillafilezilla>= 0 < 3.7.3-13.7.3-1
puttyputty
puttyputty
puttyputty
puttyputty
puttyputty
puttyputty
puttyputty
puttyputty
puttyputty
puttyputty
puttyputty
puttyputty
puttyputty
puttyputty
puttyputty
puttyputty
puttyputty
puttyputty
puttyputty>= 0 < 0.63-10.63-1

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.