cbcvebase.

Debian Putty vulnerabilities

25 known vulnerabilities affecting debian/putty.

Total CVEs
25
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH7MEDIUM5LOW8

Vulnerabilities

Page 2 of 2
CVE-2003-0048P4MEDIUMCVSS 4.6fixed in putty 0.53-b-2003-01-04-1 (bookworm)2003
CVE-2003-0048 [MEDIUM] CVE-2003-0048: putty - PuTTY 0.53b and earlier does not clear logon credentials from memory, including ... PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials. Scope: local bookworm: resolved (fixed in 0.53-b-2003-01-04-1) bullseye: resolved (fixed in 0.53-b-2003-01-04-1) forky: resolved (fixed in 0.53-b-2003-01-04-1) sid: resolved (fixed in 0.53-
debian
CVE-2011-4607P4LOWCVSS 2.1fixed in putty 0.62-1 (bookworm)2011
CVE-2011-4607 [LOW] CVE-2011-4607: putty - PuTTY 0.59 through 0.61 does not clear sensitive process memory when managing us... PuTTY 0.59 through 0.61 does not clear sensitive process memory when managing user replies that occur during keyboard-interactive authentication, which might allow local users to read login passwords by obtaining access to the process' memory. Scope: local bookworm: resolved (fixed in 0.62-1) bullseye: resolved (fixed in 0.62-1) forky: resolved (fixed in 0.62-1) sid: res
debian
CVE-2013-4208P4LOWCVSS 2.1fixed in filezilla 3.7.3-1 (bookworm)2013
CVE-2013-4208 [LOW] CVE-2013-4208: filezilla - The rsa_verify function in PuTTY before 0.63 (1) does not clear sensitive proces... The rsa_verify function in PuTTY before 0.63 (1) does not clear sensitive process memory after use and (2) does not free certain structures containing sensitive process memory, which might allow local users to discover private RSA and DSA keys. Scope: local bookworm: resolved (fixed in 3.7.3-1) bullseye: resolved (fixed in 3.7.3-1) forky: resolved (fixed in 3.7.3-1)
debian
CVE-2015-2157P4LOWCVSS 2.1fixed in putty 0.63-10 (bookworm)2015
CVE-2015-2157 [LOW] CVE-2015-2157: putty - The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 thro... The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory. Scope: local bookworm: resolved (fixed in 0.63-10) bullseye: resolved (fixed in 0.63-10) forky: resolved (fixed in 0.63-10) sid: resolved (fixed in 0.6
debian
CVE-2006-7162P4LOWCVSS 1.9fixed in putty 0.59-1 (bookworm)2006
CVE-2006-7162 [LOW] CVE-2006-7162: putty - PuTTY 0.59 and earlier uses weak file permissions for (1) ppk files containing p... PuTTY 0.59 and earlier uses weak file permissions for (1) ppk files containing private keys generated by puttygen and (2) session logs created by putty, which allows local users to gain sensitive information by reading these files. Scope: local bookworm: resolved (fixed in 0.59-1) bullseye: resolved (fixed in 0.59-1) forky: resolved (fixed in 0.59-1) sid: resolved (fixed
debian
Debian Putty vulnerabilities | cvebase