Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6,...
Vulnerability Description
Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a denial of service (crash) and possibly execute arbitrary code in certain applications that use PuTTY via a negative size value in an RSA key signature during the SSH handshake, which triggers a heap-based buffer overflow.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-4852
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/54533
- http://secunia.com/advisories/54517
- http://winscp.net/tracker/show_bug.cgi?id=1017
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=718779
- http://www.search-lab.hu/advisories/secadv-20130722
- http://www.debian.org/security/2013/dsa-2736
- http://svn.tartarus.org/sgt?view=revision&sortby=date&revision=9896
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00035.html
- http://secunia.com/advisories/54379
- http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-signature-stringlen.html
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00041.html
More from winscp
View All →Affected Vendor
winscp
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.