Debian Putty vulnerabilities
25 known vulnerabilities affecting debian/putty.
Total CVEs
25
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH7MEDIUM5LOW8
Vulnerabilities
Page 1 of 2
CVE-2023-48795P1MEDIUMCVSS 5.9ExploitedPoCfixed in dropbear 2022.83-1+deb12u1 (bookworm)2023
CVE-2023-48795 [MEDIUM] CVE-2023-48795: dropbear - The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH bef...
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabl
debian
CVE-2016-2563P2CRITICALCVSS 9.8PoCfixed in putty 0.67-1 (bookworm)2016
CVE-2016-2563 [CRITICAL] CVE-2016-2563: putty - Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67...
Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows remote servers to cause a denial of service (stack memory corruption) or execute arbitrary code via a crafted SCP-SINK file-size response to an SCP download request.
Scope: local
bookworm: resolved (fixed in 0.67-1)
bullseye: resolved (fixed in 0.67
debian
CVE-2017-6542P2CRITICALCVSS 9.8PoCfixed in putty 0.67-3 (bookworm)2017
CVE-2017-6542 [CRITICAL] CVE-2017-6542: putty - The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers...
The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol message and leveraging the ability to connect to the Unix-domain socket representing the forwarded agent connection, which trigger a buffer overflow.
Scope: local
bookworm: resolved (fixed in 0.67-3)
bullseye: reso
debian
CVE-2019-9895P3CRITICALCVSS 9.8fixed in putty 0.70-6 (bookworm)2019
CVE-2019-9895 [CRITICAL] CVE-2019-9895: putty - In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow ex...
In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client forwarding.
Scope: local
bookworm: resolved (fixed in 0.70-6)
bullseye: resolved (fixed in 0.70-6)
forky: resolved (fixed in 0.70-6)
sid: resolved (fixed in 0.70-6)
trixie: resolved (fixed in 0.70-6)
debian
CVE-2019-9898P3CRITICALCVSS 9.8fixed in putty 0.70-6 (bookworm)2019
CVE-2019-9898 [CRITICAL] CVE-2019-9898: putty - Potential recycling of random numbers used in cryptography exists within PuTTY b...
Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.
Scope: local
bookworm: resolved (fixed in 0.70-6)
bullseye: resolved (fixed in 0.70-6)
forky: resolved (fixed in 0.70-6)
sid: resolved (fixed in 0.70-6)
trixie: resolved (fixed in 0.70-6)
debian
CVE-2021-36367P3HIGHCVSS 8.1fixed in putty 0.75-3 (bookworm)2021
CVE-2021-36367 [HIGH] CVE-2021-36367: putty - PuTTY through 0.75 proceeds with establishing an SSH session even if it has neve...
PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user).
Scope: loc
debian
CVE-2004-1008P3CRITICALCVSS 10.0fixed in putty 0.56-1 (bookworm)2004
CVE-2004-1008 [CRITICAL] CVE-2004-1008: putty - Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows ...
Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DEBUG packet with a modified stringlen parameter, which leads to a buffer overflow.
Scope: local
bookworm: resolved (fixed in 0.56-1)
bullseye: resolved (fixed in 0.56-1)
forky: resolved (fixed in 0.56-1)
sid: resolved (fixed in 0
debian
CVE-2024-31497P3MEDIUMCVSS 5.9fixed in filezilla 3.67.0-1 (forky)2024
CVE-2024-31497 [MEDIUM] CVE-2024-31497: filezilla - In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an ...
In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. This is especially important in a scenario where an adversary is able to read messages signed by PuTTY or Pageant. The required set of signed messages may be publicly readable becaus
debian
CVE-2019-9894P3HIGHCVSS 7.5fixed in putty 0.70-6 (bookworm)2019
CVE-2019-9894 [HIGH] CVE-2019-9894: putty - A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71...
A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.
Scope: local
bookworm: resolved (fixed in 0.70-6)
bullseye: resolved (fixed in 0.70-6)
forky: resolved (fixed in 0.70-6)
sid: resolved (fixed in 0.70-6)
trixie: resolved (fixed in 0.70-6)
debian
CVE-2019-9897P3HIGHCVSS 7.5fixed in putty 0.70-6 (bookworm)2019
CVE-2019-9897 [HIGH] CVE-2019-9897: putty - Multiple denial-of-service attacks that can be triggered by writing to the termi...
Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.
Scope: local
bookworm: resolved (fixed in 0.70-6)
bullseye: resolved (fixed in 0.70-6)
forky: resolved (fixed in 0.70-6)
sid: resolved (fixed in 0.70-6)
trixie: resolved (fixed in 0.70-6)
debian
CVE-2019-17068P3HIGHCVSS 7.5fixed in putty 0.73-1 (bookworm)2019
CVE-2019-17068 [HIGH] CVE-2019-17068: putty - PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, wh...
PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboard content.
Scope: local
bookworm: resolved (fixed in 0.73-1)
bullseye: resolved (fixed in 0.73-1)
forky: resolved (fixed in 0.73-1)
sid: resolved (fixed in 0.73-1)
trixie: resolved (fixed in 0.73-1)
debian
CVE-2013-4852P4LOWCVSS 6.8fixed in filezilla 3.7.3-1 (bookworm)2013
CVE-2013-4852 [MEDIUM] CVE-2013-4852: filezilla - Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other produ...
Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a denial of service (crash) and possibly execute arbitrary code in certain applications that use PuTTY via a negative size value in an RSA key signature during the SSH handshake, which triggers a heap-based buffer overflow.
Scope: l
debian
CVE-2019-17069P4LOWCVSS 7.5fixed in putty 0.73-1 (bookworm)2019
CVE-2019-17069 [HIGH] CVE-2019-17069: putty - PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service ...
PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNECT message.
Scope: local
bookworm: resolved (fixed in 0.73-1)
bullseye: resolved (fixed in 0.73-1)
forky: resolved (fixed in 0.73-1)
sid: resolved (fixed in 0.73-1)
trixie: resolved (fixed in 0.73-1)
debian
CVE-2004-1440P4HIGHCVSS 7.5fixed in putty 0.56-1 (bookworm)2004
CVE-2004-1440 [HIGH] CVE-2004-1440: putty - Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55...
Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via an SSH2 packet with a base argument that is larger than the mod argument, which causes the modpow function to write memory before the beginning of its buffer, and (2) remote malicious servers to cause a denial of service (client crash
debian
CVE-2005-0467P4HIGHCVSS 7.5fixed in putty 0.57-1 (bookworm)2005
CVE-2005-0467 [HIGH] CVE-2005-0467: putty - Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_rec...
Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that corrupt the heap after insufficient memory has been allocated.
Scope: local
bookworm: resolved (fixed in 0.57-1)
bullsey
debian
CVE-2020-14002P4MEDIUMCVSS 5.9fixed in putty 0.74-1 (bookworm)2020
CVE-2020-14002 [MEDIUM] CVE-2020-14002: putty - PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information ...
PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client).
Scope: local
bookworm: resolved (fixed in 0.74-1)
bullseye: resolved (fixed in 0.74-1)
forky: resolved (fixed
debian
CVE-2013-4206P4LOWCVSS 6.8fixed in filezilla 3.7.3-1 (bookworm)2013
CVE-2013-4206 [MEDIUM] CVE-2013-4206: filezilla - Heap-based buffer underflow in the modmul function in sshbn.c in PuTTY before 0....
Heap-based buffer underflow in the modmul function in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (crash) and possibly trigger memory corruption or code execution via a crafted DSA signature, which is not properly handled when performing certain bit-shifting operations during modular multiplication.
Scope: local
bookworm: re
debian
CVE-2003-0069P4HIGHCVSS 7.5fixed in putty 0.54-1 (bookworm)2003
CVE-2003-0069 [HIGH] CVE-2003-0069: putty - The PuTTY terminal emulator 0.53 allows attackers to modify the window title via...
The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
Scope: local
bookworm: resolved (fixed in 0.54-1)
bullseye
debian
CVE-2015-5309P4MEDIUMCVSS 4.3fixed in putty 0.66-1 (bookworm)2015
CVE-2015-5309 [MEDIUM] CVE-2015-5309: putty - Integer overflow in the terminal emulator in PuTTY before 0.66 allows remote att...
Integer overflow in the terminal emulator in PuTTY before 0.66 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via an ECH (erase characters) escape sequence with a large parameter value, which triggers a buffer underflow.
Scope: local
bookworm: resolved (fixed in 0.66-1)
bullseye: resolved (fixed in 0.66-1)
f
debian
CVE-2013-4207P4LOWCVSS 6.8fixed in filezilla 3.7.3-1 (bookworm)2013
CVE-2013-4207 [MEDIUM] CVE-2013-4207: filezilla - Buffer overflow in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cau...
Buffer overflow in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (crash) via an invalid DSA signature that is not properly handled during computation of a modular inverse and triggers the overflow during a division by zero by the bignum functionality, a different vulnerability than CVE-2013-4206.
Scope: local
bookworm: resolve
debian
1 / 2Next →