CVE-2015-5309 — Out-of-bounds Write in Tatham Putty
Severity
4.3MEDIUMNVD
EPSS
1.7%
top 17.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 7
Latest updateMay 14
Description
Integer overflow in the terminal emulator in PuTTY before 0.66 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via an ECH (erase characters) escape sequence with a large parameter value, which triggers a buffer underflow.
CVSS vector
AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9
Affected Packages4 packages
🔴Vulnerability Details
3📋Vendor Advisories
1Debian▶
CVE-2015-5309: putty - Integer overflow in the terminal emulator in PuTTY before 0.66 allows remote att...↗2015
💬Community
4Bugzilla▶
CVE-2015-5309 putty: Integer overflow and buffer underrun in terminal emulator's ECH handling [epel-5]↗2015-11-09
Bugzilla▶
CVE-2015-5309 putty: Integer overflow and buffer underrun in terminal emulator's ECH handling [fedora-all]↗2015-11-09
Bugzilla▶
CVE-2015-5309 putty: Integer overflow and buffer underrun in terminal emulator's ECH handling [epel-6]↗2015-11-09
Bugzilla▶
CVE-2015-5309 putty: Integer overflow and buffer underrun in terminal emulator's ECH handling↗2015-11-09